Files
CVEs-PoC/2021/CVE-2021-21580.md
T
2024-05-25 21:48:12 +02:00

19 lines
988 B
Markdown

### [CVE-2021-21580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21580)
![](https://img.shields.io/static/v1?label=Product&message=Integrated%20Dell%20Remote%20Access%20Controller%20(iDRAC)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%205.00.00.00%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-74%3A%20Improper%20Neutralization%20of%20Special%20Elements%20in%20Output%20Used%20by%20a%20Downstream%20Component%20('Injection')&color=brighgreen)
### Description
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/chnzzh/iDRAC-CVE-lib