CVE-2025-26482
MEDIUMDell PowerEdge Server BIOS and iDRAC9 - Information Disclosure via Uncleared Debug Information
Title source: llmDescription
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
References (1)
Core 1
Core References
Scores
CVSS v3
4.9
EPSS
0.0004
EPSS Percentile
13.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1258
Status
published
Products (50)
dell/dss_8440_firmware
< 2.23.0
dell/emc_nx440_firmware
< 2.18.0
dell/emc_storage_nx3240_firmware
< 2.23.0
dell/emc_storage_nx3340_firmware
< 2.23.0
dell/emc_xc_core_6420_system_firmware
< 2.23.0
dell/emc_xc_core_xc450_firmware
< 1.16.2
dell/emc_xc_core_xc640_system_firmware
< 2.23.0
dell/emc_xc_core_xc650_firmware
< 1.16.2
dell/emc_xc_core_xc6520_firmware
< 1.16.2
dell/emc_xc_core_xc740xd2_firmware
< 2.23.0
... and 40 more
Published
Sep 25, 2025
Tracked Since
Feb 18, 2026