CVE-2018-1244: Dell IDRAC7 Firmware

High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled.

Affected products

  • Dell IDRAC7 Firmware: before 2.60.60.60 (fixed in 2.60.60.60)
  • Dell IDRAC8 Firmware: before 2.60.60.60 (fixed in 2.60.60.60)
  • Dell IDRAC9 Firmware: before 3.21.21.21 (fixed in 3.21.21.21)

Published 2018-07-02. Last modified 2026-06-17.