Database/Firmware, BMC & network fabric
Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystem
CVE-2025-22397Firmware, BMC & network fabriccurated
Impact
A high-privileged remote attacker traverses paths on the BMC filesystem, reaching high confidentiality and availability impact. Post-compromise this is how an attacker persists in the BMC.
Who can reach it
Authenticated high-privilege access to iDRAC9 (14G/15G/16G) or iDRAC10 (17G).
What to do
Update to iDRAC9 7.00.00.181 / past 7.20.10.50, or iDRAC10 1.20.25.00. BMC flash. Because it needs high privilege, the compensating control is tight iDRAC RBAC and no shared admin credentials across the fleet.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.