CVE-2026-70412: Low severity Dell iDRAC9 vulnerability
Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell iDRAC9to a version that resolves this vulnerability.Fixed in 7.20.30.50 - Upgrade
Upgrade
Dell iDRAC10to a version that resolves this vulnerability.Fixed in 1.20.60.50
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70412?
CVE-2026-70412 has a severity rating of low with a score of 3.5.
How do I fix CVE-2026-70412?
To mitigate CVE-2026-70412, upgrade Dell iDRAC9 to version 7.20.30.50 or later, and Dell iDRAC10 to version 1.20.60.50 or later.
What type of vulnerability is CVE-2026-70412?
CVE-2026-70412 is classified as a Remanent Data Readable after Memory Erase vulnerability.
Who is affected by CVE-2026-70412?
CVE-2026-70412 affects users of Dell iDRAC9 and Dell iDRAC10 with versions prior to the specified updates.
Can CVE-2026-70412 be exploited remotely?
Yes, a low privileged attacker with remote access could potentially exploit CVE-2026-70412.