CVE-2018-15774: Dell IDRAC7 Firmware
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and 3.23.23.23 contain a privilege escalation vulnerability. An authenticated malicious iDRAC user with operator privileges could potentially exploit a permissions check flaw in the Redfish interface to gain administrator access.
Affected products
- Dell IDRAC7 Firmware: before 2.61.60.60 (fixed in 2.61.60.60)
- Dell IDRAC8 Firmware: before 2.61.60.60 (fixed in 2.61.60.60)
- Dell IDRAC9 Firmware: before 3.20.21.20 (fixed in 3.20.21.20); from 3.21.21.21, before 3.21.24.22 (fixed in 3.21.24.22)
Published 2018-12-13. Last modified 2026-06-17.