Database/Firmware, BMC & network fabric
Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC console
Impact
Unauthenticated access to the iDRAC VNC console. Same practical outcome as an unauthenticated KVM: the attacker watches and drives the tenant's console, can reach the boot menu and firmware setup, and can chain into Virtual Media to boot an attacker image below the hypervisor. Affects iDRAC9 5.00.00.00 up to 5.10.10.00, so it hits the 15G PowerEdge generation that a lot of first-wave GPU fleets standardised on.
Who can reach it
Anything routable to the iDRAC VNC port on the management VLAN, unauthenticated - but only where the iDRAC VNC server has actually been enabled. It is off by default, so the real exposure is the subset of nodes where someone turned it on for remote hands.
What to do
Flash iDRAC9 to 5.10.10.00 or later - out-of-band, per-node, no host reboot and no job drain (iDRAC self-resets, brief OOB blackout only). Because VNC is opt-in, the fastest mitigation is config-only and costs nothing: audit which nodes have the iDRAC VNC server enabled and turn it off. That closes the hole fleet-wide in minutes while the firmware campaign runs on its own schedule.
References
Related entries
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCVE-2023-37293 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executedCVE-2024-27892 · Arista EOS (OpenConfig gNMI Set authorization)Critical
- IBM Power FSP: malformed ASMI request gives unauthenticated code execution on the service processorCVE-2026-16687 · IBM Power Systems Firmware (FSP service processor, ASMI web interface)Critical
- IBM Power FSP: management protocol authentication bypass yields full administrative control of the hostCVE-2026-16835 · IBM Power Systems Firmware (FSP management network protocol authentication)Critical
- Arista EOS P4Runtime: unauthenticated client can gain full administrative control of the switchCVE-2026-73453 · Arista EOS (P4Runtime service)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.