Impact
Dell iDRAC9 firmware versions before 7.00.00.182 (14G) or before 7.20.30.50 (15G/16G) contain an Improper Access Control flaw. An unauthenticated attacker who can reach the iDRAC interface over the network can exploit this weakness and obtain data that should be restricted to authorized personnel. The flaw does not grant full system control but can expose sensitive configuration, logs, or credentials stored within iDRAC. Affected systems include Dell iDRAC9 14G releases earlier than 7.00.00.182 and 15G or 16G releases earlier than 7.20.30.50. These firmware versions are distributed across many Dell servers that use remote management. The CVSS score of 5.9 places the vulnerability in the medium severity range. Because the EPSS metric is not available, the likelihood of exploitation cannot be quantified from the data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote unauthenticated access to the iDRAC web interface, as the description specifies an "unauthenticated attacker with remote access".
Affected Systems
Dell iDRAC9 14G firmware prior to 7.00.00.182 and Dell iDRAC9 15G/16G firmware prior to 7.20.30.50.
Risk and Exploitability
A moderate severity flaw that allows an attacker to read protected data over the network. The lack of an EPSS rating and KEV listing suggests limited known exploitation, but the remote nature and lack of authentication make it a meaningful risk in exposed environments.
OpenCVE Enrichment