MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-22397

CVSS 6.7v3.1pub. 2025-11-06upd. 2026-01-21

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H
  • Dell Idrac10

    HW
    Dell
    all versions
  • Dell Idrac10 Firmware

    OS
    Dell
    < 1.20.25.00
  • Dell Idrac9

    HW
    Dell
    all versions
  • Dell Idrac9 Firmware

    OS
    Dell
    6.10.80.00 – 7.00.00.181 (excl.)7.00.00.183 – 7.20.10.50 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2022-24422CRITICAL9.6PL ✓same product

Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)

CVE-2021-21538CRITICAL9.6PL ✓same product

Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli

CVE-2019-3705CRITICAL9.8PL ✓same product

Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE

CVE-2026-35155HIGH7.1same product

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerabili...

CVE-2024-25943HIGH7.6same product

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...