Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2014-8272

Description

The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.

POC

Reference

- http://www.kb.cert.org/vuls/id/843044

- http://www.kb.cert.org/vuls/id/BLUU-9RDQHM

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ZtczGrowtopia/2500-OPEN-SOURCE-RAT

- https://github.com/chnzzh/iDRAC-CVE-lib