CVE-2026-23855

Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung

mediumEPSS 0.9%

Description

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.

Source: BSI

Metrics

Severity
medium
no public PoC known
7.2
Source: cna-v3
58.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-10 11:37 UTC
CWE-78

Weakness classes (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-11 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-23855","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-23855","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-09-09 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-23855","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-09 17:17 UTC· security_alert@emc.com
    • Description: Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-78
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/23xxx/CVE-2026-23855.json">CVE-2026-23855</a>

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Dell

    integrated Dell Remote Access Controller10 <1.30.30.50

  • Dell

    integrated Dell Remote Access Controller9 <7.00.00.184

  • Dell

    integrated Dell Remote Access Controller9 <7.30.10.50

References & sources

Linked CVEs

IDCVE-2026-23855