Stack-based Buffer Overflow in Dell PowerEdge Products
CVE-2025-26336

9.8CRITICAL

Summary

The Chassis Management Controller firmware for Dell PowerEdge FX2 and VRTX is susceptible to a stack-based buffer overflow vulnerability. An unauthenticated attacker possessing remote access could exploit this issue, potentially allowing for unauthorized remote code execution on the affected devices. Users are advised to update their firmware to the recommended versions to mitigate this risk. For more details, refer to the vendor advisory.

Affected Version(s)

Dell Chassis Management Controller (CMC) for Dell PowerEdge FX2 < 2.40.200.202101130302

Dell Chassis Management Controller (CMC) for PowerEdge VRTX < 3.41.200.202209300499

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank Aliz Hammond of watchTowr for reporting these issues
.