Database/Firmware, BMC & network fabric
Dell iDRAC Tools (improper access control): A low-privileged local attacker escalates privileges through the iDRAC
CVE-2025-27689Firmware, BMC & network fabriccurated
Impact
A low-privileged local attacker escalates privileges through the iDRAC Tools package on the management workstation or jump host where it is installed.
Who can reach it
Local low-privilege access to a host running iDRAC Tools below 11.3.0.0.
What to do
Upgrade iDRAC Tools to 11.3.0.0. This lives on admin workstations and provisioning servers, not the GPU nodes - so the fix is a management-plane package update, but those hosts hold fleet-wide BMC credentials.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.