CVE-2018-1249 describes a vulnerability in Dell EMC iDRAC9 firmware versions prior to 3.21.21.21 where certain web server URLs failed to enforce TLS/SSL. This flaw allows a man-in-the-middle attacker to strip SSL/TLS protection, compromising the confidentiality of communication between a client and the iDRAC web server. The vulnerability is rated Medium (CVSS 5.9) due to its network-based attack vector and high impact on confidentiality, though it requires high attack complexity. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.21.21.21CPE matchmatch criteria | cpe:2.3:o:dell:idrac9_firmware:*:*:*:*:*:*:*:* | ||
< 3.21.21.21CPE match | cpe:2.3:a:dell:idrac9:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.