Dell Chassis Management Controller Stack-Based Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Dell Chassis Management Controller (CMC) Firmware for PowerEdge FX2, versions prior to 2.40.200.202101130302, and for PowerEdge VRTX, versions prior to 3.41.200.202209300499. This vulnerability allows an unauthenticated attacker with remote access to potentially execute code remotely.

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected system.

Remediation

Users can upgrade to Dell Chassis Management Controller (CMC) version 2.41.200.202503050519 or later for PowerEdge FX2, and version 3.42.200.202503050519 or later for PowerEdge VRTX. Instructions for downloading the updated firmware are available on the Dell Support website.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.