Dell Integrated Dell Remote Access Controller Process Control Vulnerability Allowing Code Execution

Vulnerability

A process control vulnerability has been identified in Dell Integrated Dell Remote Access Controller (iDRAC) 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50, and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00. This vulnerability allows a high-privileged attacker with adjacent network access to potentially execute code on the affected system.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the affected system.

Remediation

Users can upgrade to iDRAC9 versions 7.00.00.181 or later, or iDRAC10 versions 1.20.25.00 or later. For iDRAC9, drivers are available on the Dell Support website. Instructions for downloading the updated drivers can be found in the Dell Security Advisory DSA-2026-113.

Added: Mar 18, 2026, 7:28 PM
Updated: Mar 18, 2026, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
7.5
exploitability
3.0
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.