CVE-2026-79940: Medium severity Dell iDRAC9 vulnerability
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell iDRAC9to a version that resolves this vulnerability.Fixed in 7.00.00.182 - Upgrade
Upgrade
Dell iDRAC 15G/16Gto a version that resolves this vulnerability.Fixed in 7.20.30.50
Event History
Frequently Asked Questions
Which systems are affected by this issue?
Dell iDRAC9 14G systems running versions earlier than 7.00.00.182 are affected, as are Dell iDRAC9 15G/16G systems running versions earlier than 7.20.30.50.
Does exploitation require authentication or user interaction?
No. The vulnerability may be exploited by an unauthenticated attacker with remote access, and no user interaction is required. The attack complexity is rated high.
What is the potential impact if the vulnerability is exploited?
Successful exploitation could allow an attacker to gain access to unauthorized data. The provided severity vector indicates integrity impact, with no stated confidentiality or availability impact.