Impact
Dell iDRAC9 and iDRAC10 expose remanent data that remains readable after memory erasure. A low‑privileged attacker who can reach the device remotely may read previously stored data, potentially revealing sensitive configuration or system information. The weakness is identified as a remanent data leakage flaw.
Affected Systems
Dell iDRAC9 models running any version before 7.20.30.50 and Dell iDRAC10 models running any version before 1.20.60.50 are subject to this vulnerability.
Risk and Exploitability
The CVSS base score of 3.5 assigns a low severity to this flaw. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, indicating a modest exploitation probability. Successful exploitation requires remote access with low privileges; no public exploit is documented, and the attack surface is limited to users who can reach the iDRAC interfaces.
OpenCVE Enrichment