Description
Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-08-17
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell iDRAC9 and iDRAC10 expose remanent data that remains readable after memory erasure. A low‑privileged attacker who can reach the device remotely may read previously stored data, potentially revealing sensitive configuration or system information. The weakness is identified as a remanent data leakage flaw.

Affected Systems

Dell iDRAC9 models running any version before 7.20.30.50 and Dell iDRAC10 models running any version before 1.20.60.50 are subject to this vulnerability.

Risk and Exploitability

The CVSS base score of 3.5 assigns a low severity to this flaw. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, indicating a modest exploitation probability. Successful exploitation requires remote access with low privileges; no public exploit is documented, and the attack surface is limited to users who can reach the iDRAC interfaces.

Generated by OpenCVE AI on August 17, 2026 at 14:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell iDRAC9 to version 7.20.30.50 or later
  • Upgrade Dell iDRAC10 to version 1.20.60.50 or later
  • Restrict remote management access to iDRAC interfaces and enforce strong authentication

Generated by OpenCVE AI on August 17, 2026 at 14:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remanent Data Readable After Memory Erase in Dell iDRAC9 and iDRAC10
First Time appeared Dell
Dell idrac10
Dell idrac9
Vendors & Products Dell
Dell idrac10
Dell idrac9

Mon, 17 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-1330
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-17T14:31:28.807Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70412

cve-icon Vulnrichment

Updated: 2026-08-17T14:31:05.551Z

cve-icon NVD

Status : Received

Published: 2026-08-17T13:16:52.737

Modified: 2026-08-17T15:16:57.390

Link: CVE-2026-70412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T14:45:04Z

Weaknesses
  • CWE-1330

    Remanent Data Readable after Memory Erase