ZeroHour

CVE-2026-23855

large

OS Command Injection in Dell iDRAC9 and iDRAC10 (High-Privilege)

CVSS 3.1
7.2 high
EPSS
<1%p59
Published
()
Modified
AI analysis

Dell iDRAC9 and iDRAC10, the out-of-band remote management controllers embedded in 14th through 17th generation PowerEdge servers, contain an OS command injection flaw (CWE-78) in which special elements in input are not properly neutralized before being passed to the underlying operating system. The flaw is exploited remotely over the network (CVSS vector AV:N) by an attacker who has already obtained high-privileged credentials on the iDRAC interface; no user interaction is required. Successful exploitation allows arbitrary OS command execution on the management controller, with high impact to confidentiality, integrity, and availability. Anyone running unpatched iDRAC9 on 14G systems (prior to 7.00.00.184), iDRAC9 on 15G/16G systems (prior to 7.30.10.50), or iDRAC10 on 17G systems (prior to 1.30.30.50) is affected. There is currently no CISA KEV listing, no known public proof-of-concept, and no confirmed in-the-wild exploitation.

What to do: Upgrade iDRAC9 on 14th-generation PowerEdge to 7.00.00.184 or later, iDRAC9 on 15G/16G systems to 7.30.10.50 or later, and iDRAC10 on 17th-generation systems to 1.30.30.50 or later. Until patched, restrict iDRAC access to dedicated management networks or VPN rather than the public internet, and review which high-privileged accounts could reach the controller. Inventory internet-facing iDRAC endpoints (management web UIs) and prioritize those patches first.

Affected
Dell iDRAC9 (PowerEdge 14th generation)prior to 7.00.00.184
Dell iDRAC9 (PowerEdge 15G/16G)prior to 7.30.10.50
Dell iDRAC10 (PowerEdge 17th generation)prior to 1.30.30.50
Estimated exposure
largelikely hundreds of thousands of internet-reachable iDRAC interfaces, and plausibly millions of deployed PowerEdge servers carrying affected iDRAC firmware — iDRAC9/iDRAC10 are the embedded out-of-band controllers on Dell's 14th-17th generation PowerEdge line, which has a very large installed base, and public internet scans have historically exposed iDRAC web endpoints on roughly hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.