CVE-2014-8272 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 19% (pctl 97)
Patch early
A public exploit exists.
Description
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 19.01% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-12-19 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| dell | idrac6 modular |
| dell | idrac6 monolithic |
| dell | idrac7 |
| intel | ipmi |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness | 2015-01-13 |
References
→ the Explorer · watch your stack · NVD