Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
History

Thu, 27 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell chassis Management Controller For Poweredge Fx2
Dell chassis Management Controller For Poweredge Fx2 Firmware
Dell chassis Management Controller For Poweredge Vrtx
Dell chassis Management Controller For Poweredge Vrtx Firmware
Weaknesses CWE-787
CPEs cpe:2.3:h:dell:chassis_management_controller_for_poweredge_fx2:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:chassis_management_controller_for_poweredge_vrtx:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chassis_management_controller_for_poweredge_fx2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:chassis_management_controller_for_poweredge_vrtx_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell chassis Management Controller For Poweredge Fx2
Dell chassis Management Controller For Poweredge Fx2 Firmware
Dell chassis Management Controller For Poweredge Vrtx
Dell chassis Management Controller For Poweredge Vrtx Firmware

Fri, 21 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Mar 2025 02:45:00 +0000

Type Values Removed Values Added
Description Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-03-21T13:59:49.924Z

Reserved: 2025-02-07T06:04:04.738Z

Link: CVE-2025-26336

cve-icon Vulnrichment

Updated: 2025-03-21T13:59:44.740Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-21T03:15:12.000

Modified: 2025-03-27T16:08:17.900

Link: CVE-2025-26336

cve-icon Redhat

No data.