Known vulnerabilities in iDRAC9

Vendor: Dell
Software: iDRAC9
Software CPE: cpe:2.3:a:dell:idrac9:*:*:*:*:*:*:*:*
Total vulnerabilities: 43
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting iDRAC9 iDRAC9 is affected by 43 known vulnerabilities: 12 high, 19 medium, 12 low Critical High Medium Low

Vulnerabilities (43)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU104034 - Improper input validation
CVE-2025-26466
CWE-20 Medium
Available
No
7.00.00.181, 7.20.30.50 18.02.2025 SB2025021815
SB2025021830
SB2025021840
and 25 more
#VU100566 - Off-by-one Error
CVE-2024-52533
CWE-193 High
No
No
7.00.00.181, 7.20.30.50 15.11.2024 SB20241115147
SB20241115148
SB20241115149
and 71 more
#VU99614 - Improper input validation
CVE-2024-50602
CWE-20 Medium
No
No
7.00.00.181, 7.20.30.50 01.11.2024 SB2024110155
SB2024110182
SB2024110534
and 98 more
#VU96899 - Integer overflow
CVE-2024-45492
CWE-190 High
No
No
7.00.00.181, 7.20.30.50 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 108 more
#VU96898 - Integer overflow
CVE-2024-45491
CWE-190 High
No
No
7.00.00.181, 7.20.30.50 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 106 more
#VU96897 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-45490
CWE-124 High
No
No
7.00.00.181, 7.20.30.50 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 113 more
#VU95093 - Improper input validation
CVE-2024-42154
CWE-20 Low
No
No
7.00.00.174 31.07.2024 SB20240731176
SB2024081301
SB2024081648
and 64 more
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
7.00.00.173, 7.10.50.10 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU88822 - Memory corruption
CVE-2024-2961
CWE-119 High
Available
Exploited
7.00.00.181, 7.20.30.50 18.04.2024 SB2024041855
SB2024041856
SB2024041857
and 107 more
#VU88378 - Resource exhaustion
CVE-2023-52340
CWE-400 Medium
No
No
7.00.00.174 10.04.2024 SB2024041034
SB2024041037
SB2024041038
and 80 more
#VU85935 - Integer overflow
CVE-2023-6780
CWE-190 Low
No
No
7.00.00.181, 7.20.30.50 31.01.2024 SB2024013126
SB2024013135
SB2024013136
and 6 more
#VU77351 - Improper input validation
CVE-2023-29499
CWE-20 Medium
No
No
7.00.00.172, 7.10.50.00 15.06.2023 SB2023041955
SB2023061510
SB2023080276
and 35 more
#VU75574 - Permissions, Privileges, and Access Controls
CVE-2022-34435
CWE-264 Medium
No
No
6.00.30.00 28.04.2023 SB2023042804
SB2023042805
SB2023081529
#VU69364 - Memory corruption
CVE-2022-44640
CWE-119 High
No
No
6.10.30.20, 6.10.39.00 16.11.2022 SB2022111610
SB2022111621
SB2022112302
and 16 more
#VU66177 - Improper Authentication
CVE-2022-24422
CWE-287 High
No
No
5.10.10.00 08.08.2022 SB2022081045
SB2022111419
SB2022111730
and 1 more
#VU66170 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-36348
CWE-74 Medium
No
No
5.00.20.00 08.08.2022 SB2022081044
SB2022092810
SB2023010516
and 1 more
#VU66164 - Stack-based buffer overflow
CVE-2021-36347
CWE-121 Low
No
No
5.00.10.20 08.08.2022 SB2022012658
SB2022092810
SB2023010516
and 1 more
#VU66163 - Improper input validation
CVE-2021-36346
CWE-20 Medium
Available
No
4.40.29.00, 4.40.40.00, 5.00.00.00, 5.00.10.00 08.08.2022 SB2022092810
SB2022111803
SB2023010516
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
5.10.30.00 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
4.40.29.00, 4.40.40.00, 5.00.00.00, 5.00.10.00 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more


Showing elements 1 - 20 out of 43