GPU VulnDB

Database/Firmware, BMC & network fabric

Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes control

CVE-2024-25951Firmware, BMC & network fabriccurated

Impact

An authenticated user injects commands through local RACADM and takes control of the underlying BMC operating system - full out-of-band control of the server from an ordinary iDRAC account.

Who can reach it

Adjacent-network attacker holding any valid low-privilege iDRAC credential.

What to do

Apply the iDRAC8 firmware update from DSA-2024-089. BMC firmware flash, no host reboot. Review iDRAC local accounts at the same time - the bug converts a low-privilege account into root on the BMC.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.