CVE-2025-38742: Medium severity Dell iDRAC Service Module vulnerability
Published Aug 21, 2025
·Updated
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Affected Software
2 affected components
Dell iDRAC Service Module<6.0.3.0
Dell EMC iDRAC Service Module<6.0.3.0
Event History
Aug 21, 2025
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-38742?
CVE-2025-38742 is classified as a low severity vulnerability due to its requirement for local access to exploit.
2
How do I fix CVE-2025-38742?
To fix CVE-2025-38742, update the Dell iDRAC Service Module to version 6.0.3.0 or later.
3
Who is affected by CVE-2025-38742?
CVE-2025-38742 affects users running versions of Dell iDRAC Service Module prior to 6.0.3.0.
4
What type of vulnerability is CVE-2025-38742?
CVE-2025-38742 is an Incorrect Permission Assignment for Critical Resource vulnerability.
5
Can CVE-2025-38742 lead to code execution?
Yes, CVE-2025-38742 can potentially allow a low privileged attacker with local access to execute code.