Stack-based Buffer Overflow in Dell PowerEdge Products
CVE-2025-26336
9.8CRITICAL
Key Information:
- Vendor
- Dell
- Status
- Vendor
- CVE Published:
- 21 March 2025
Summary
The Chassis Management Controller firmware for Dell PowerEdge FX2 and VRTX is susceptible to a stack-based buffer overflow vulnerability. An unauthenticated attacker possessing remote access could exploit this issue, potentially allowing for unauthorized remote code execution on the affected devices. Users are advised to update their firmware to the recommended versions to mitigate this risk. For more details, refer to the vendor advisory.
Affected Version(s)
Dell Chassis Management Controller (CMC) for Dell PowerEdge FX2 < 2.40.200.202101130302
Dell Chassis Management Controller (CMC) for PowerEdge VRTX < 3.41.200.202209300499
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Aliz Hammond of watchTowr for reporting these issues