CVE-2018-1207: Dell Emc IDRAC7

Critical severity, CVSS 9.8. EPSS: 90.1% chance of exploitation in the next 30 days.

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.

Affected products

  • Dell Emc IDRAC7: before 2.52.52.52 (fixed in 2.52.52.52)
  • Dell Emc IDRAC8: before 2.52.52.52 (fixed in 2.52.52.52)

Published 2018-03-23. Last modified 2026-06-17.