iDRACula Dell EMC PowerEdge Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Dell EMC PowerEdge servers
- Dell EMC PowerEdge servers - Generation 12 and 13
- Dell iDRAC - Firmware versions prior to 9
Dell iDRAC
Threat details
iDRAC is a proprietary baseboard management controller (BMC) used by Dell EMC PowerEdge servers for remote administration and control purposes. It operates independently of the operating system and applications present on a server.
The vulnerability lies in how iDRAC checks external content that is delivered to it. Any user with valid iDRAC credentials is able to escalate their privileges to gain access to a root Linux shell, they will then be able to load any file or code they wish without the iDRAC verifying or checking their content.
As the iDRAC is entirely separate from the server itself, any changes made to it are difficult to detect. An attacker can load their own operating system or BIOS that will be hidden, even from other iDRAC users, and can be used to deliver any malware the attacker wishes to the server.
Remediation advice
Dell EMC have confirmed that an update to address this vulnerability is being produced. Organisations are encouraged to contact their relevant suppliers and apply this update as soon as it becomes available. Guidance on how to update the iDRAC can be found here.Remediation steps
Last edited: 17 February 2020 12:45 pm