CVE-2024-25951: Command Injection
Published Mar 9, 2024
·Updated
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
Affected Software
1 affected component
Dell iDRAC8<2.85.85.85
Event History
Mar 9, 2024
CVE Published
via MITRE·05:56 AM
Data Sourced
via MITRE·05:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25951?
CVE-2024-25951 is considered a critical vulnerability due to its potential to allow a malicious authenticated user to gain control of the underlying operating system.
2
How do I fix CVE-2024-25951?
To fix CVE-2024-25951, update the Dell iDRAC8 Firmware to version 2.85.85.85 or later.
3
Who is affected by CVE-2024-25951?
CVE-2024-25951 affects users of Dell iDRAC8 Firmware versions prior to 2.85.85.85.
4
Is a patch available for CVE-2024-25951?
Yes, Dell has released a security update to address CVE-2024-25951.
5
What are the potential impacts of CVE-2024-25951?
The potential impacts of CVE-2024-25951 include unauthorized access and control over the operating system, leading to possible data breaches or system manipulation.