Database/Control plane, storage & DevOps
Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack buffer
Impact
Unauthenticated remote attacker overflows a stack buffer in the CMC and gains control of the chassis manager - the component that owns power, identity and console for every sled in the enclosure.
Who can reach it
Network access to the CMC management interface, no credentials required.
What to do
Update CMC firmware to 2.40.200.202101130302 (FX2) or 3.41.200.202209300499 (VRTX). Firmware flash on the chassis controller; sleds keep running but management is interrupted. If these chassis are reachable from anything but a locked-down OOB VLAN, fix that first - it is the actual exposure.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.