CVE-2018-1244: Dell IDRAC7 Firmware
High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled.
Affected products
- Dell IDRAC7 Firmware: before 2.60.60.60 (fixed in 2.60.60.60)
- Dell IDRAC8 Firmware: before 2.60.60.60 (fixed in 2.60.60.60)
- Dell IDRAC9 Firmware: before 3.21.21.21 (fixed in 3.21.21.21)
Published 2018-07-02. Last modified 2026-06-17.