Database/Firmware, BMC & network fabric
Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server's
Impact
An attacker with no credentials lands directly inside the server's Virtual Console - the same screen-and-keyboard the operator uses. From there they see whatever the tenant is running, drive the BIOS/boot menu, and pair it with Virtual Media to boot a node off an image they supply. On a bare-metal cloud that is a silent cross-tenant handoff failure: the previous or a neighbouring tenant's session is visible and controllable without ever touching the production network. Only iDRAC9 firmware in the 4.40.00.00-4.40.09.99 band is affected, so this is a narrow-window regression that is easy to miss in a mixed-vintage fleet.
Who can reach it
Anything routable to the iDRAC address on the out-of-band management VLAN, no account and no prior foothold. If the OOB network is flat across racks, a single compromised jump host or a mis-scoped VPN split-tunnel reaches every node in the affected firmware band.
What to do
Flash iDRAC9 to 4.40.10.00 or later. This is per-node but fully out-of-band (iDRAC web UI, racadm, Redfish SimpleUpdate, or OME) and does NOT require a host reboot - the iDRAC resets itself and you lose OOB reachability for roughly two to five minutes while the host keeps running its jobs. No drain needed. Immediate config-only mitigation while you roll: disable Virtual Console and Virtual Media under iDRAC Settings, and ACL the management VLAN down to the jump hosts.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.