← back
CVE-2024-25951highCWE-1288

CVE-2024-25951

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
In short

An authenticated user can inject malicious commands into RACADM (a Dell remote management tool) to take control of the underlying operating system. This is dangerous because someone with login credentials can bypass normal security restrictions and run unauthorized commands.

Technical detail

RACADM contains a command injection vulnerability (CWE-1288) that allows authenticated users to execute arbitrary operating system commands. The attack requires valid authentication credentials and can result in complete system compromise with OS-level privileges.

Summary generated and translated by AI from the official description.
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H