HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-35155

CVSS 7.1v3.1pub. 2026-04-29upd. 2026-05-01

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Dell Idrac10

    HW
    Dell
    all versions
  • Dell Idrac10 Firmware

    OS
    Dell
    < 1.30.10.50
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Race Condition
CWE
References

Related vulnerabilities

CVE-2025-22397MEDIUM6.7same product

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10....

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-67261CRITICAL9.8PL ✓same vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)

CVE-2026-54489CRITICAL9.1PL ✓same vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta

CVE-2026-46738CRITICAL9.1PL ✓same vendor

Dell PowerProtect Data Manager – Improper Input Validation w REST API (privilege escalation)