DSA-2026-198: Security Update for Dell Precision Rack for Multiple iDRAC9 Vulnerabilities
Summary: Dell iDRAC9 with Lifecycle Controller remediation for Dell Precision Rack is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system. ...
Impact
High
Details
|
Third-Party Component |
CVEs |
More Information |
|
OpenSSL |
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-26945 |
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution. |
5.3 |
|
|
CVE-2026-26948 |
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. |
4.9 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-26945 |
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution. |
5.3 |
|
|
CVE-2026-26948 |
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. |
4.9 |
Affected Products & Remediation
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2026-26945 |
Precision 7920 Rack |
iDRAC9 |
Versions prior to 7.00.00.181 |
Versions 7.00.00.181 or later |
|
|
CVE-2026-26945 |
Precision 7920 XL Rack |
iDRAC9 |
Versions prior to 7.00.00.181 |
Versions 7.00.00.181 or later |
|
|
CVE-2026-26945 |
Precision 7960 Rack |
iDRAC9 |
Versions prior to 7.20.10.50 |
Versions 7.20.10.50 or later |
|
|
CVE-2026-26945 |
Precision 7960 XL Rack |
iDRAC9 |
Versions prior to 7.20.10.50 |
Versions 7.20.10.50 or later |
|
|
CVE-2026-26948 |
Precision 7920 Rack |
iDRAC9 |
Versions prior to 7.00.00.174 |
Versions 7.00.00.174 or later |
|
|
CVE-2026-26948 |
Precision 7920 XL Rack |
iDRAC9 |
Versions prior to 7.00.00.174 |
Versions 7.00.00.174 or later |
|
|
CVE-2026-26948 |
Precision 7960 Rack |
iDRAC9 |
Versions prior to 7.10.90.00 |
Versions 7.10.90.00 or later |
|
|
CVE-2026-26948 |
Precision 7960 XL Rack |
iDRAC9 |
Versions prior to 7.10.90.00 |
Versions 7.10.90.00 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7920 Rack |
iDRAC9 |
Versions prior to 7.00.00.184 |
Versions 7.00.00.184 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7920 XL Rack |
iDRAC9 |
Versions prior to 7.00.00.184 |
Versions 7.00.00.184 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7960 Rack |
iDRAC9 |
Versions prior to 7.30.10.50 |
Versions 7.30.10.50 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7960 XL Rack |
iDRAC9 |
Versions prior to 7.30.10.50 |
Versions 7.30.10.50 or later |
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2026-26945 |
Precision 7920 Rack |
iDRAC9 |
Versions prior to 7.00.00.181 |
Versions 7.00.00.181 or later |
|
|
CVE-2026-26945 |
Precision 7920 XL Rack |
iDRAC9 |
Versions prior to 7.00.00.181 |
Versions 7.00.00.181 or later |
|
|
CVE-2026-26945 |
Precision 7960 Rack |
iDRAC9 |
Versions prior to 7.20.10.50 |
Versions 7.20.10.50 or later |
|
|
CVE-2026-26945 |
Precision 7960 XL Rack |
iDRAC9 |
Versions prior to 7.20.10.50 |
Versions 7.20.10.50 or later |
|
|
CVE-2026-26948 |
Precision 7920 Rack |
iDRAC9 |
Versions prior to 7.00.00.174 |
Versions 7.00.00.174 or later |
|
|
CVE-2026-26948 |
Precision 7920 XL Rack |
iDRAC9 |
Versions prior to 7.00.00.174 |
Versions 7.00.00.174 or later |
|
|
CVE-2026-26948 |
Precision 7960 Rack |
iDRAC9 |
Versions prior to 7.10.90.00 |
Versions 7.10.90.00 or later |
|
|
CVE-2026-26948 |
Precision 7960 XL Rack |
iDRAC9 |
Versions prior to 7.10.90.00 |
Versions 7.10.90.00 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7920 Rack |
iDRAC9 |
Versions prior to 7.00.00.184 |
Versions 7.00.00.184 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7920 XL Rack |
iDRAC9 |
Versions prior to 7.00.00.184 |
Versions 7.00.00.184 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7960 Rack |
iDRAC9 |
Versions prior to 7.30.10.50 |
Versions 7.30.10.50 or later |
|
|
CVE-2025-11187, CVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 |
Precision 7960 XL Rack |
iDRAC9 |
Versions prior to 7.30.10.50 |
Versions 7.30.10.50 or later |
Revision History
"
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-05-11 | Initial Release |