Database/Firmware, BMC & network fabric
Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9
Impact
Information disclosure spanning both the BIOS and iDRAC9 on a very large PowerEdge model list - and that list explicitly includes the GPU platforms: XE9680, XE9680L, XE9640 and XE8640. Low severity in isolation; what makes it worth tracking is coverage. If you run Dell GPU nodes, this one almost certainly applies to your exact SKUs, and disclosed platform/firmware detail is the reconnaissance that makes a later BMC or BIOS exploit reliable rather than a guess.
Who can reach it
A high-privilege attacker with remote access - i.e. someone who already holds an administrative iDRAC credential. This is a post-compromise information-leak rather than an entry point, which is why the score is moderate.
What to do
Two separate rollouts. The iDRAC9 side is an out-of-band firmware flash, per-node, no host reboot, no drain. The BIOS side needs a System BIOS update that applies only on the next reboot, so it costs a drain of running training jobs - for XE9680-class nodes that is a real scheduling problem, since those are the machines you least want to take down. Sequence the iDRAC flash immediately and batch the BIOS update into the next planned maintenance window. Per-model version floors are in the advisory (e.g. 2.5.4 for the R660/R760 family, 1.2.6 for the R470/R570/R670/R770 family).
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.