Database/Firmware, BMC & network fabric
Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes control
CVE-2024-25951Firmware, BMC & network fabriccurated
Impact
An authenticated user injects commands through local RACADM and takes control of the underlying BMC operating system - full out-of-band control of the server from an ordinary iDRAC account.
Who can reach it
Adjacent-network attacker holding any valid low-privilege iDRAC credential.
What to do
Apply the iDRAC8 firmware update from DSA-2024-089. BMC firmware flash, no host reboot. Review iDRAC local accounts at the same time - the bug converts a low-privilege account into root on the BMC.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.