← Vulnerability feed

Vulnerability record · CVE-2013-3589 · published 24 September 2013

CVE-2013-3589: Dell idrac6 firmware cross-site scripting vulnerability

Dell · Idrac6 Firmware

Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.

4.3 CVSS 2.0 Medium EPSS 1.6% · top 24.7% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.kb.cert.org/vuls/id/920038 US Government Resource
http://www.kb.cert.org/vuls/id/BLUU-997QVW US Government Resource
http://www.kb.cert.org/vuls/id/920038 US Government Resource
http://www.kb.cert.org/vuls/id/BLUU-997QVW US Government Resource

Track CVE-2013-3589 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4785Dell idrac6 firmware vulnerabilityThe web interface on the Dell iDRAC6 with firmware before 1.95 allows remote attackers to modify the CLP interface for arbitrary users and possibly h…EPSS 3.6%9.8CVE-2020-5344Dell idrac7 firmware stack-based buffer overflow vulnerabilityDell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unaut…EPSS 3.8%9.8CVE-2019-3705Dell idrac6 firmware classic buffer overflow vulnerabilityDell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 a…EPSS 4.2%8.8CVE-2018-15774Dell idrac7 firmware incorrect authorization vulnerabilityDell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privile…EPSS 0.94%8.8CVE-2018-1212Dell idrac6 modular command injection vulnerabilityThe web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulner…EPSS 4.3%8.8CVE-2018-1244Dell idrac7 firmware command injection vulnerabilityDell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP a…EPSS 3.4%8.8CVE-2016-5685Dell idrac7 firmware injection vulnerabilityDell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.EPSS 1.8%7.5CVE-2018-1243Dell idrac6 firmware vulnerabilityDell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI ses…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2013-3589), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.