CVE-2024-25943: Dell IDRAC9

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.

Affected products

  • Dell IDRAC9: before 7.00.00.172 (fixed in 7.00.00.172); before 7.10.50.00 (fixed in 7.10.50.00)

Published 2024-06-29. Last modified 2026-06-17.