← Vulnerability feed

Vulnerability record · CVE-2021-21510 · published 8 March 2021

CVE-2021-21510: Dell idrac8 firmware improper input validation vulnerability

Dell · Idrac8 Firmware

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

6.1 CVSS 3.1 Medium EPSS 1.0% · top 37.8% CWE-20 · Improper input validationCWE-74 · Injection
6.1CVSS 3.1 base score, v2 5.8
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21510 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-5344Dell idrac7 firmware stack-based buffer overflow vulnerabilityDell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unaut…EPSS 3.8%9.8CVE-2019-3705Dell idrac6 firmware classic buffer overflow vulnerabilityDell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 a…EPSS 4.2%8.8CVE-2018-15774Dell idrac7 firmware incorrect authorization vulnerabilityDell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privile…EPSS 0.94%8.8CVE-2018-1244Dell idrac7 firmware command injection vulnerabilityDell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP a…EPSS 3.4%8.8CVE-2016-5685Dell idrac7 firmware injection vulnerabilityDell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.EPSS 1.8%7.5CVE-2018-1243Dell idrac6 firmware vulnerabilityDell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI ses…EPSS 1.8%6.8CVE-2018-15776Dell idrac7 firmware vulnerabilityDell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical acces…EPSS 0.42%4.9CVE-2022-34436Dell idrac8 firmware improper input validation vulnerabilityDell iDRAC8 version 2.83.83.83 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is se…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2021-21510), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.