CVE-2018-1211: Dell Emc IDRAC7

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI strings.

Affected products

  • Dell Emc IDRAC7: before 2.52.52.52 (fixed in 2.52.52.52)
  • Dell Emc IDRAC8: before 2.52.52.52 (fixed in 2.52.52.52)

Published 2018-03-23. Last modified 2026-06-17.