CVE-2025-38742: Dell Emc Idrac Service Module
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Affected products
- Dell Emc Idrac Service Module: before 6.0.3.0 (fixed in 6.0.3.0)
Published 2025-08-21. Last modified 2026-06-17.