Database/Firmware, BMC & network fabric
Dell iDRAC Service Module (incorrect default permissions): Weak default folder permissions let an unprivileged local
CVSS 7.0CVE-2024-22428Firmware, BMC & network fabriccurated
Impact
Weak default folder permissions let an unprivileged local user escalate and execute code on the host.
Who can reach it
Any local unprivileged user on a server running iSM 5.2.0.0 or earlier.
What to do
Upgrade iSM past 5.2.0.0. Host package update; no reboot required.
References
Related entries
- Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620CVE-2024-47975 · Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620…High
- Intel Xeon 6 with TDX: overlapping protected memory ranges in SMM allow privilege escalationCVE-2025-31936 · Intel Xeon 6 processors with Intel TDX (protected memory range overlap handling in SMM)High
- EDK II (SMM environment, Machine Check Exception handling): Machine Check Exceptions are enabled before SMM installsCVE-2025-3770 · EDK II (SMM environment, Machine Check Exception handling)High
- Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management trafficCVE-2026-16792 · Lenovo XClarity Orchestrator 2.2.0 (microservice TLS certificate validation)High
- Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436: Improper authenticationCVE-2026-20885 · Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436High
- Arista EOS: crafted OSPFv3 packets restart the Ospf3 agent and drop all adjacenciesCVE-2026-73438 · Arista EOS Ospf3 agent (OSPFv3 packet handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.