CVE-2024-25951: Dell IDRAC8

High severity, CVSS 8.0. EPSS: 0.8% chance of exploitation in the next 30 days.

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

Affected products

  • Dell IDRAC8: before 2.85.85.85 (fixed in 2.85.85.85)

Published 2024-03-09. Last modified 2026-06-17.