Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.
References
| Link | Resource |
|---|---|
| https://www.dell.com/support/kbdoc/en-us/000452298/dsa-2026-187-security-update-for-dell-idrac10-vulnerability | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
01 May 2026, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.dell.com/support/kbdoc/en-us/000452298/dsa-2026-187-security-update-for-dell-idrac10-vulnerability - Vendor Advisory | |
| CPE | cpe:2.3:o:dell:idrac10_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dell:idrac10:-:*:*:*:*:*:*:* |
|
| First Time |
Dell idrac10
Dell Dell idrac10 Firmware |
30 Apr 2026, 15:13
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-29 05:16
Updated : 2026-05-01 17:40
NVD link : CVE-2026-35155
Mitre link : CVE-2026-35155
CVE.ORG link : CVE-2026-35155
JSON object : View
Products Affected
dell
- idrac10_firmware
- idrac10
CWE
CWE-522
Insufficiently Protected Credentials
