← Vulnerability feed

Vulnerability record · CVE-2021-21576 · published 3 August 2021

CVE-2021-21576: Dell emc idrac9 firmware cross-site scripting vulnerability

Dell · Emc Idrac9 Firmware

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

6.1 CVSS 3.1 Medium EPSS 0.75% · top 47.0% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21576 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2021-36300Dell emc idrac9 firmware sql injection vulnerabilityiDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit th…EPSS 33%8.1CVE-2021-36299Dell emc idrac9 firmware sql injection vulnerabilityDell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated mali…EPSS 30%7.2CVE-2021-36301Dell emc idrac8 firmware stack-based buffer overflow vulnerabilityDell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote a…EPSS 28%6.1CVE-2021-21579Dell emc idrac9 firmware open redirect vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…EPSS 0.82%6.1CVE-2021-21581Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerabi…EPSS 0.75%6.1CVE-2021-21577Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this…EPSS 0.75%6.1CVE-2021-21578Dell emc idrac9 firmware open redirect vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…EPSS 0.82%4.3CVE-2021-21580Dell emc idrac8 firmware injection vulnerabilityDell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a mali…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2021-21576), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.