DSA-2026-077: Security Update for Dell iDRAC Service Module Vulnerability

Sommaire: Dell iDRAC Service Module remediation is available for a privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system.

Cet article s’applique à Cet article ne s’applique pas à Cet article n’est lié à aucun produit spécifique. Toutes les versions de produits ne sont pas identifiées dans cet article.

Impact

High

Détails

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2026-23856

Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2026-23856

Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommande à tous ses clients de tenir compte à la fois du score de base CVSS et de tous les scores temporels et environnementaux pertinents qui pourraient avoir une incidence sur la gravité potentielle associée à une vulnérabilité de sécurité particulière.

Produits touchés et correction

Product

Affected Versions

Remediated Versions

Link

iDRAC Service Module for Windows

Versions prior to 5.4.1.1

Version 5.4.1.1 or later

Dell EMC iDRAC Service Module for Win, v5.4.1.1 | Driver Details | Dell US

iDRAC Service Module for Windows

Versions prior to 6.0.3.1

Version 6.0.3.1 or later

Dell iDRAC Service Module for Win, v6.0.3.1 | Driver Details | Dell US

iDRAC Service Module for Linux

Versions prior to 5.4.1.1

Version 5.4.1.1 or later

Dell iDRAC Service Module for Linux, v5.4.1.1 | Driver Details | Dell US

 

Product

Affected Versions

Remediated Versions

Link

iDRAC Service Module for Windows

Versions prior to 5.4.1.1

Version 5.4.1.1 or later

Dell EMC iDRAC Service Module for Win, v5.4.1.1 | Driver Details | Dell US

iDRAC Service Module for Windows

Versions prior to 6.0.3.1

Version 6.0.3.1 or later

Dell iDRAC Service Module for Win, v6.0.3.1 | Driver Details | Dell US

iDRAC Service Module for Linux

Versions prior to 5.4.1.1

Version 5.4.1.1 or later

Dell iDRAC Service Module for Linux, v5.4.1.1 | Driver Details | Dell US

 

The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

Historique de révision

Revision

Date

Description

1.0

2026-02-10

Initial Release

 

Reconnaissances

Dell would like to thank falconCorrup for reporting this issue.

Renseignements connexes

Produits touchés

iDRAC Service Module 1.x, iDRAC Service Module 2.x, iDRAC Service Module 4.x, iDRAC Service Module 5.x, iDRAC Service Module 3.x
Propriétés de l’article
Numéro d’article: 000426282
Type d’article: Dell Security Advisory
Dernière modification: 10 févr. 2026
Obtenez des réponses à vos questions auprès d’autre utilisateurs de Dell
Services de soutien
Vérifiez si votre appareil est couvert par les services de soutien.