CVE-2026-70412
3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Summary
Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | iDRAC9 | 0 < 7.20.30.50 or later | affected |
| Dell | iDRAC10 | 0 < 1.20.60.50 or later | affected |
Weaknesses
- CWE-1330: CWE-1330: Remanent Data Readable after Memory Erase
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.