CVE-2025-38742: Dell Emc Idrac Service Module

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Affected products

  • Dell Emc Idrac Service Module: before 6.0.3.0 (fixed in 6.0.3.0)

Published 2025-08-21. Last modified 2026-06-17.