Impact
This vulnerability stems from improper neutralization of special elements used in OS command strings, enabling OS Command Injection on Dell iDRAC9 and iDRAC10. An attacker with high privileges and remote access could inject arbitrary commands, potentially executing code with the privileges of the iDRAC process and compromising firmware and host systems. The weakness is catalogued as CWE-78.
Affected Systems
Affected devices include Dell iDRAC9 for 14G versions earlier than 7.00.00.184, 15G/16G versions earlier than 7.30.10.50, and Dell iDRAC10 for 17G versions earlier than 1.30.30.50. All affected firmware revisions are from Dell.
Risk and Exploitability
The CVSS score of 7.2 indicates substantial risk, and the EPSS score is not available, with no listing in the KEV catalog. Because the problem requires high privileged remote access, the likelihood of exploitation depends on attacker presence in the network; no public exploit has been reported, yet the possibility for a targeted breach remains significant.
OpenCVE Enrichment