5.9
CVE-2026-79940
- EPSS 0.18%
- Veröffentlicht 26.08.2026 18:16:42
- Zuletzt bearbeitet 28.08.2026 15:29:44
- Erkennungen
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDell
≫
Produkt
iDRAC9
Default Statusunaffected
Version
0
Version <
7.20.30.50 or later
Status
affected
Version
0
Version <
7.00.00.182 or later
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.077 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| EMC | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://www.dell.com/support/kbdoc/en-us/000502514/dsa-2026-374-security-update-for-dell-idrac9-vulnerability