CNNVD-202511-520 Information

CNNVD ID

CNNVD-202511-520

CVE-2025-22397

  • CNNVD Published: 2025-11-06

Description (Chinese)

Dell iDRAC9和Dell iDRAC10都是美国戴尔(Dell)公司的产品。Dell iDRAC9是提供提供整个的PowerEdge系列服务器全面,嵌入式管理,自动化功能。一个控制器。Dell iDRAC10是一款集成远程访问控制器。 Dell iDRAC9和Dell iDRAC10存在路径遍历漏洞,该漏洞源于路径限制不当,可能导致未经授权的访问。

Description (English)

Dell iDRAC9 and Dell iDRAC10 are products of Dell in the United States. Dell iDRAC9 provides full, embedded and automated access to the PowerEdge series of servers. A controller. Dell iDRAC10 is an integrated remote access controller. Dell iDRAC9 and Dell iDRAC10 have a loophole in their path, which stems from inappropriate path limitations and may lead to unauthorized access.

Hazard Level

High

Vulnerability Type

路径遍历

Affected Vendor

戴尔

Published

2025-11-06

Last Modified

2026-02-24

References

https://www.dell.com/support/kbdoc/en-us/000384516/dsa-2025-376-security-update-for-dell-idrac9-and-idrac10-vulnerabilities

Patch

https://www.dell.com/support/kbdoc/en-us/000384516/dsa-2025-376-security-update-for-dell-idrac9-and-idrac10-vulnerabilities

Share on: