Database/Firmware, BMC & network fabric
Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystem
CVSS 6.7CVE-2025-22397Firmware, BMC & network fabriccurated
Impact
A high-privileged remote attacker traverses paths on the BMC filesystem, reaching high confidentiality and availability impact. Post-compromise this is how an attacker persists in the BMC.
Who can reach it
Authenticated high-privilege access to iDRAC9 (14G/15G/16G) or iDRAC10 (17G).
What to do
Update to iDRAC9 7.00.00.181 / past 7.20.10.50, or iDRAC10 1.20.25.00. BMC flash. Because it needs high privilege, the compensating control is tight iDRAC RBAC and no shared admin credentials across the fleet.
References
Related entries
- IBM Power Systems host firmware: crafted service-processor command leaks protected registersCVE-2026-19321 · IBM Power Systems host firmware (service processor register access path)Medium
- Junos mgd: null pointer dereference on an SSH configuration change crashes the management daemonCVE-2026-21901 · Juniper Junos OS / Junos OS Evolved management daemon (mgd)Medium
- HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmwareCVE-2018-7113 · HPE iLO 5 (firmware update security restriction bypass)Medium
- AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareCVE-2023-34473 · AMI MegaRAC SPx (BMC hard-coded credentials)Medium
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPCVE-2024-20294 · Cisco FXOS / NX-OS (LLDP frame handling denial of service)Medium
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: The PMU firmware on Zynq UltraScale+CVE-2025-0038 · AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.