← Vulnerability feed

Vulnerability record · CVE-2021-36301 · published 23 November 2021

CVE-2021-36301: Dell emc idrac8 firmware stack-based buffer overflow vulnerability

Dell · Emc Idrac8 Firmware

Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.

7.2 CVSS 3.1 High EPSS 28% · top 2.0% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
7.2CVSS 3.1 base score, v2 6.5
28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://support.emc.com/kb/000191229 PatchVendor Advisory
https://support.emc.com/kb/000191229 PatchVendor Advisory

Track CVE-2021-36301 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2021-36300Dell emc idrac9 firmware sql injection vulnerabilityiDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit th…EPSS 33%8.1CVE-2021-36299Dell emc idrac9 firmware sql injection vulnerabilityDell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated mali…EPSS 30%6.1CVE-2021-21579Dell emc idrac9 firmware open redirect vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…EPSS 0.82%6.1CVE-2021-21581Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 5.00.00.00 contain a cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerabi…EPSS 0.75%6.1CVE-2021-21576Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this…EPSS 0.75%6.1CVE-2021-21577Dell emc idrac9 firmware cross-site scripting vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this…EPSS 0.75%6.1CVE-2021-21578Dell emc idrac9 firmware open redirect vulnerabilityDell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability…EPSS 0.82%4.3CVE-2021-21580Dell emc idrac8 firmware injection vulnerabilityDell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a mali…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2021-36301), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.