CVE-2016-5685: Dell IDRAC7 Firmware

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.

Affected products

  • Dell IDRAC7 Firmware: up to and including 2.30.30.30
  • Dell IDRAC8 Firmware: up to and including 2.30.30.30

Published 2016-11-29. Last modified 2026-06-17.