7.2
CVE-2026-23855
- EPSS 0.93%
- Veröffentlicht 09.09.2026 16:02:57
- Zuletzt bearbeitet 11.09.2026 04:17:40
- Erkennungen
Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDell
≫
Produkt
iDRAC9
Default Statusunaffected
Version
0
Version <
7.30.10.50 or later
Status
affected
Version
0
Version <
7.00.00.184 or later
Status
affected
HerstellerDell
≫
Produkt
iDRAC10
Default Statusunaffected
Version
0
Version <
1.30.30.50 or later
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.93% | 0.586 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| EMC | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.dell.com/support/kbdoc/en-us/000504998/dsa-2026-392-security-update-for-dell-idrac9-and-idrac10-vulnerability