Dell Dell EMC iDRAC Response to Vulnerabilities Described in CVE-2018-1249 CVE-2018-1244 CVE-2018-1212 CVE-2018-1243 Owner's Manual User Guide
Summary
This security advisory details Dell EMC's response to critical iDRAC vulnerabilities including CVE-2018-1249, CVE-2018-1244, CVE-2018-1212, and CVE-2018-1243. Covers TLS enforcement issues, SNMP command injection, diagnostics console injection, and weak session ID vulnerabilities. Provides affected versions and firmware update resolutions. Intended for security professionals maintaining secure iDRAC deployments.
Page 1 Text Content
Dell EMC i DRAC Response to Vulnerabilities Described in CVE-2018-1249, CVE-2018-1244, CVE-2018-1212, CVE-2018-1243 [updated 20 Sept 2018]
OVERVIEW
The following is Dell EMC’s response to multiple CVEs in Integrated Dell Remote Access Controller (i DRAC). i DRAC firmware versions listed below contain fixes for these security vulnerabilities that could potentially be exploited by malicious users to compromise the affected system.
CVE Identifiers: CVE-2018-1249 (Medium), CVE-2018-1244 (High), CVE-2018-1212 (High), CVE-2018-1243 (High)
TECHNICAL SUMMARY • CVE-2018-1249: Dell EMC i DRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to i DRAC web server for certain URLs. A man-in-the-middle attacker could use this vulnerability to strip the SSL/TLS protection from a connection between a client and a server. • CVE-2018-1244: Dell EMC i DRAC7/i DRAC8, versions prior to 2.60.60.60, and i DRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious i DRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the i DRAC where SNMP alerting is enabled. • CVE-2018-1212: The web-based diagnostics console in Dell EMC i DRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious i DRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected i DRAC system. • CVE-2018-1243: Dell EMC i DRAC6, versions prior to 2.91, i DRAC7/i DRAC8, versions prior to 2.60.60.60 and i DRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only session ID values, which makes it easier for remote attackers to perform brute-force session guessing attacks.
RESOLUTION The following Dell EMC i DRAC firmware releases contain resolutions to these vulnerabilities: • Dell EMC i DRAC6 version 2.91 for Monolithic servers (CVE-2018-1243 and CVE-2018-1212) • Dell EMC i DRAC7/i DRAC8 version 2.60.60.60 (CVE-2018-1244 and CVE-2018-1243) • Dell EMC i DRAC9 version 3.21.21.21 (CVE-2018-1249, CVE-2018-1244 and CVE-2018-1243)
Dell EMC recommends all customers upgrade at the earliest opportunity. Dell EMC recommends that customers take into account any deployment factors that may be relevant to their environment to assess their overall risk.
Page Summary Contents For Dell Dell EMC iDRAC Response to Vulnerabilities Described in CVE-2018-1249 CVE-2018-1244 CVE-2018-1212 CVE-2018-1243 Owner's Manual User Guide
Manual Details
| Brand | Dell |
|---|---|
| Pages | 2 |
| File Size | 382.62 KB |
| Published | June 26, 2026 |
Enter the captcha to get the download link:
Frequently Asked Questions
Which firmware fixes the weakest CGI session ID vulnerability (CVE-2018-1243) across all iDRAC models?
iDRAC9 version 3.21.21.21 resolves CVE-2018-1243, along with other older versions for specific hardware.
What is the recommended security deployment practice for iDRAC units?
iDRACs should be on a separate management network and not connected directly to the Internet.
How can I disable the iDRAC web interface if I cannot upgrade? (iDRAC6 Modular)
You can disable it using the iDRAC GUI or via RACADM: racadm config -g cfgRacTuning -o cfgRacTuneWebserverEnable 0.
What specific vulnerability is addressed by upgrading to iDRAC9 version 3.21.21.21?
This update provides fixes for CVE-2018-1249 (TLS/SSL enforcement failure), CVE-2018-1244 (SNMP command injection), and CVE-2018-1243.