Dell TechnologiesCVE-2026-70412
Dell Technologies iDRAC10: information disclosure
Low3.5CVE-2026-70412 · Published Aug 17, 2026 · updated Aug 18, 2026
Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iDRAC10 Product | < 1.20.60.50 or later | 1.20.60.50 or later |
| iDRAC9 Product | < 7.20.30.50 or later | 7.20.30.50 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1330
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Dell Technologies ObjectScale: uncontrolled search path | High7.3 | 4.3.0.1 or later |
| Aug 17 | Dell Technologies ObjectScale: command injection | High7.3 | 4.3.0.1 or later |
| Aug 17 | Dell Technologies ObjectScale: command injection | High7.8 | 4.3.0.1 or later |
| Aug 17 | Dell Technologies ObjectScale: path traversal | High7.1 | 4.3.0.1 or later |
| Aug 17 | Dell Technologies ObjectScale: command injection | High7.8 | 4.3.0.1 or later |
| Aug 17 | Dell Technologies ObjectScale: information disclosure | Medium5.5 | 4.3.0.1 or later |