Database/Firmware, BMC & network fabric
Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes control
CVSS 8.0CVE-2024-25951Firmware, BMC & network fabriccurated
Impact
An authenticated user injects commands through local RACADM and takes control of the underlying BMC operating system - full out-of-band control of the server from an ordinary iDRAC account.
Who can reach it
Adjacent-network attacker holding any valid low-privilege iDRAC credential.
What to do
Apply the iDRAC8 firmware update from DSA-2024-089. BMC firmware flash, no host reboot. Review iDRAC local accounts at the same time - the bug converts a low-privilege account into root on the BMC.
References
Related entries
- Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by gettingCVE-2024-37774 · Sunbird DCIM dcTrack v9.1.2High
- NVIDIA UFM Enterprise: code injection via the plugin management API from a low-privileged accountCVE-2026-24169 · NVIDIA UFM Enterprise (plugin management API)High
- librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125: RDMACVE-2012-4516 · librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125High
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-45745 · Intel TDX moduleHigh
- Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management): An unauthenticated local attackerCVE-2024-0172 · Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management)High
- AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-drivenCVE-2024-21980 · AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.