Database/Firmware, BMC & network fabric
Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes the
Impact
A string injection escapes the restricted racadm command interface and drops the caller into a real Bash shell on the service processor. Any BMC account - including the low-privilege, read-only kind an operator hands to a customer or an NOC contractor for power-cycling their own node - becomes arbitrary code execution on the management controller. From a shell on the iDRAC an attacker persists across host reinstalls, tampers with the host's firmware update path, and watches or drives the host console. This is the pre-2018 example of why 'we only gave them limited BMC access' is not a boundary: the restricted CLI was the boundary, and it is one quoting bug deep.
Who can reach it
Network, post-auth. Any valid iDRAC credential, at any privilege level, over SSH or the racadm interface.
What to do
Flash iDRAC7/iDRAC8 firmware to 2.40.40.40 or later - an out-of-band update that does not require host downtime, roughly 10-15 minutes per node with a brief loss of management access, so it can be run against live nodes if you accept that window. The policy change worth making alongside it: stop issuing per-tenant or per-vendor BMC accounts at all. Broker power and console operations through your own control plane so tenants never hold a credential on the service processor, which removes this entire class rather than this one instance of it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.