CVE-2018-1211: Dell Emc IDRAC7
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI strings.
Affected products
- Dell Emc IDRAC7: before 2.52.52.52 (fixed in 2.52.52.52)
- Dell Emc IDRAC8: before 2.52.52.52 (fixed in 2.52.52.52)
Published 2018-03-23. Last modified 2026-06-17.