GPU VulnDB

Database/Firmware, BMC & network fabric

Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integrated

CVE-2021-21505Firmware, BMC & network fabricDSA-2021-020curated

Impact

Dell shipped these integrated racks with an undocumented iDRAC account whose credentials are the same everywhere. Anyone who learns them owns the BMC on every node in the system - power control, Virtual Media boot of an attacker image, KVM into the console, and a persistent foothold under the hypervisor. A shared default credential is the worst shape of this class of bug because it does not need an exploit, scales across the whole install base at once, and is invisible to a vulnerability scan that only checks firmware versions. Affects builds 1906 through 2011.

Who can reach it

Anything routable to the iDRAC addresses on the out-of-band management VLAN, using credentials that are effectively public once disclosed. No exploit, no prior foothold, no privilege escalation step.

What to do

Apply the Dell update package that brings the system to build 2102 or later. Because the root cause is an account rather than a code defect, also verify by hand afterward that the account is gone from every node's iDRAC user list, and rotate any other shared BMC credentials while you are in there. Firmware/update-package rollout is out-of-band; the account audit is config-only and should be done immediately regardless of the patch schedule.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.