VendorsDellemc_idrac_service_moduleall versions
Vulnerabilities

Dell EMC Idrac Service Module

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-22428
Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity.
Published 2024-01-16 · Modified
7.8EPSS 0.002
CVE-2025-38743
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.
Published 2025-08-21 · Analyzed
7.8EPSS 0.001
CVE-2018-11053
iSM: Dell EMC iDRAC Service Module Improper File Permission Vulnerability
Published 2018-06-26 · Modified
6.6EPSS 0.005
CVE-2024-38490
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
Published 2024-08-01 · Analyzed
5.8EPSS 0.002
CVE-2025-38742
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Published 2025-08-21 · Analyzed
5.3EPSS 0.001
CVE-2024-25947
Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
Published 2024-08-01 · Analyzed
4.8EPSS 0.002
CVE-2024-25948
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
Published 2024-08-01 · Analyzed
4.8EPSS 0.002
CVE-2024-38481
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
Published 2024-08-01 · Analyzed
4.8EPSS 0.002
CVE-2024-38489
Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.
Published 2024-08-01 · Analyzed
4.4EPSS 0.002