CVE-2019-3706 - CVE House
Back to Database
Status published High CVE-2019-3706

Web Interface Authentication Bypass Vulnerability

Vulnerability Description

Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vulnerability. A remote attacker may potentially exploit this vulnerability to bypass authentication and gain access to the system by sending specially crafted data to the iDRAC web interface.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3706

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

iDRAC
Vulnerable Versions:
3.24.24.24, 3.21.26.22, 3.22.22.22, 3.21.25.22

Timeline

Official Publish: April 26th, 2019
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.