CVE-2026-70412

Summary

Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Affected Software

VendorProductVersion RangeStatus
DelliDRAC90 < 7.20.30.50 or lateraffected
DelliDRAC100 < 1.20.60.50 or lateraffected

Weaknesses

  • CWE-1330: CWE-1330: Remanent Data Readable after Memory Erase

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References