HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2024-25951

CVSS 8.0v3.1pub. 2024-03-09upd. 2025-01-31

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Idrac8

    APP
    Dell
    < 2.85.85.85
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2020-5344HIGH7.0same product

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based ...

CVE-2016-5685HIGH8.8same product

Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell ac...

CVE-2022-34436LOW2.7same product

Dell iDRAC8 wersja 2.83.83.83 i starsze zawierają lukę związaną z nieprawidłową walidacją danych wejściowych w...

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-70419CRITICAL9.1same vendor

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...