GPU VulnDB

Database/Firmware, BMC & network fabric

Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystem

CVE-2025-22397Firmware, BMC & network fabriccurated

Impact

A high-privileged remote attacker traverses paths on the BMC filesystem, reaching high confidentiality and availability impact. Post-compromise this is how an attacker persists in the BMC.

Who can reach it

Authenticated high-privilege access to iDRAC9 (14G/15G/16G) or iDRAC10 (17G).

What to do

Update to iDRAC9 7.00.00.181 / past 7.20.10.50, or iDRAC10 1.20.25.00. BMC flash. Because it needs high privilege, the compensating control is tight iDRAC RBAC and no shared admin credentials across the fleet.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.