← Vulnerability feed

Vulnerability record · CVE-2018-1243 · published 2 July 2018

CVE-2018-1243: Dell idrac6 firmware vulnerability

Dell · Idrac6 Firmware

Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform bruteforce session guessing attacks.

7.5 CVSS 3.0 High EPSS 1.8% · top 22.1% CWE-358 · CWE-358
7.5CVSS 3.0 base score, v2 5.0
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform bruteforce session guessing attacks.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1243 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-21538Dell idrac9 firmware improper authentication vulnerabilityDell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability. A remote unauthenticated at…EPSS 1.7%10.0CVE-2013-4785Dell idrac6 firmware vulnerabilityThe web interface on the Dell iDRAC6 with firmware before 1.95 allows remote attackers to modify the CLP interface for arbitrary users and possibly h…EPSS 3.6%9.8CVE-2020-5344Dell idrac7 firmware stack-based buffer overflow vulnerabilityDell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unaut…EPSS 3.8%9.8CVE-2019-3705Dell idrac6 firmware classic buffer overflow vulnerabilityDell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 a…EPSS 4.2%9.8CVE-2019-3706Dell idrac9 firmware vulnerabilityDell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker…EPSS 3.3%9.8CVE-2019-3707Dell idrac9 firmware vulnerabilityDell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerabi…EPSS 3.3%8.8CVE-2018-15774Dell idrac7 firmware incorrect authorization vulnerabilityDell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privile…EPSS 0.94%8.8CVE-2018-1244Dell idrac7 firmware command injection vulnerabilityDell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP a…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2018-1243), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.