Database/Firmware, BMC & network fabric
Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who already
Impact
Command injection in the iDRAC SNMP agent gives an attacker who already holds an iDRAC account with configuration rights arbitrary command execution as root on the BMC itself. That is the full BMC prize: out-of-band power control, Virtual Media boot, KVM, and an implant that lives on the service processor and survives every host reimage and OS reinstall. The privilege jump matters - it converts a routine monitoring or configuration credential into persistent control of the node beneath the hypervisor.
Who can reach it
An authenticated iDRAC account holding the Configure iDRAC privilege - the kind of account handed to monitoring tooling, an integrator, or a datacenter-remote-hands team, not a full administrator. Reachability is the management VLAN.
What to do
Flash to iDRAC7/8 2.60.60.60 or iDRAC9 3.21.21.21 or later - out-of-band, per-node, no host reboot and no job drain. Config-only mitigations that reduce blast radius immediately: disable the iDRAC SNMP agent where you are not actually scraping it, and audit which service accounts hold Configure iDRAC rather than read-only. Original Dell TechCenter advisory URL is dead; NVD carries the version data.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.