CVE-2018-15776: Dell IDRAC7 Firmware

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to get access to the u-boot shell.

Affected products

  • Dell IDRAC7 Firmware: before 2.61.60.60 (fixed in 2.61.60.60)
  • Dell IDRAC8 Firmware: before 2.61.60.60 (fixed in 2.61.60.60)

Published 2018-12-13. Last modified 2026-06-17.