Database/Firmware, BMC & network fabric
Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource lets
CVSS 5.3CVE-2025-38742Firmware, BMC & network fabriccurated
Impact
Incorrect permission assignment on a critical resource lets a low-privileged local user reach code execution via the iSM agent.
Who can reach it
Low-privilege local account on the host OS.
What to do
Upgrade iSM to 6.0.3.0. Package update and service restart only.
References
Related entries
- AMD CPU microcode - bound check: An improper bound check inside AMD CPU microcode lets a malicious **guest** write intoCVE-2025-52534 · AMD CPU microcode - bound checkMedium
- AMD Secure Processor - privilege check on write path: The ASP accepts an input value and performs a writeCVE-2025-54511 · AMD Secure Processor - privilege check on write pathMedium
- Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane trafficCVE-2025-7048 · Arista EOS (MACsec process)Medium
- Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master roleCVE-2026-73444 · Arista EOS VRRPv2 IP Authentication Header (IP-AH) authenticationMedium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-002-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-004-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.