GPU VulnDB

Database/Control plane, storage & DevOps

Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack buffer

CVE-2025-26336Control plane, storage & DevOpscurated

Impact

Unauthenticated remote attacker overflows a stack buffer in the CMC and gains control of the chassis manager - the component that owns power, identity and console for every sled in the enclosure.

Who can reach it

Network access to the CMC management interface, no credentials required.

What to do

Update CMC firmware to 2.40.200.202101130302 (FX2) or 3.41.200.202209300499 (VRTX). Firmware flash on the chassis controller; sleds keep running but management is interrupted. If these chassis are reachable from anything but a locked-down OOB VLAN, fix that first - it is the actual exposure.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.