← Back

CVE-2025-22397

nvd nist
Published: Nov 6, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Affected (3)

2 products
Idrac9 Firmware
Idrac10 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dell
From 6.10.80.00 to 7.00.00.181
From 7.00.00.183 to 7.20.10.50
Running on/withPlatform Versions
Dell
Idrac9
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.20.25.00
Running on/withPlatform Versions
Dell
Idrac10
All versions

Timeline

No history available yet.