Skip to main content

iDRACula Dell EMC PowerEdge Vulnerability

A vulnerability in Dell EMC's Integrated Dell Remote Administration Controller (iDRAC) has been disclosed by security researchers. A remote attacker could exploit this vulnerability to deliver and execute malicious code undetected on an affected device.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability in Dell EMC's Integrated Dell Remote Administration Controller (iDRAC) has been disclosed by security researchers. A remote attacker could exploit this vulnerability to deliver and execute malicious code undetected on an affected device.

Affected platforms

The following platforms are known to be affected:

Dell EMC PowerEdge servers

  • Dell EMC PowerEdge servers - Generation 12 and 13
  • Dell iDRAC - Firmware versions prior to 9

Dell iDRAC

Threat details

iDRAC is a proprietary baseboard management controller (BMC) used by Dell EMC PowerEdge servers for remote administration and control purposes. It operates independently of the operating system and applications present on a server.

The vulnerability lies in how iDRAC checks external content that is delivered to it. Any user with valid iDRAC credentials is able to escalate their privileges to gain access to a root Linux shell, they will then be able to load any file or code they wish without the iDRAC verifying or checking their content.

As the iDRAC is entirely separate from the server itself, any changes made to it are difficult to detect. An attacker can load their own operating system or BIOS that will be hidden, even from other iDRAC users, and can be used to deliver any malware the attacker wishes to the server.


Remediation advice

Dell EMC have confirmed that an update to address this vulnerability is being produced. Organisations are encouraged to contact their relevant suppliers and apply this update as soon as it becomes available. Guidance on how to update the iDRAC can be found here.

Remediation steps

Type Step
iDRAC modules can also be disabled on affected servers, although organisations should be aware that this removes all remote administration capabilities provide by the iDRAC.

Last edited: 17 February 2020 12:45 pm