← Vulnerability feed

Vulnerability record · CVE-2021-21580 · published 3 August 2021

CVE-2021-21580: Dell emc idrac8 firmware injection vulnerability

Dell · Emc Idrac8 Firmware

Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.

4.3 CVSS 3.1 Medium EPSS 0.69% · top 49.1% CWE-74 · Injection
4.3CVSS 3.1 base score, v2 4.3
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phish users into believing that the message is legitimate.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2021-36300Dell emc idrac9 firmware sql injection vulnerabilityiDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit th…EPSS 33%8.1CVE-2021-36299Dell emc idrac9 firmware sql injection vulnerabilityDell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated mali…EPSS 30%7.2CVE-2021-36301Dell emc idrac8 firmware stack-based buffer overflow vulnerabilityDell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote a…EPSS 28%6.1CVE-2021-21579Dell emc idrac9 firmware open redirect vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…EPSS 0.82%6.1CVE-2021-21581Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerabi…EPSS 0.75%6.1CVE-2021-21576Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this…EPSS 0.75%6.1CVE-2021-21577Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this…EPSS 0.75%6.1CVE-2021-21578Dell emc idrac9 firmware open redirect vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…EPSS 0.82%

Source: NIST National Vulnerability Database (record CVE-2021-21580), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.