CVE-2025-26336

Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:chassis_management_controller_for_poweredge_fx2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:chassis_management_controller_for_poweredge_fx2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:chassis_management_controller_for_poweredge_vrtx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:chassis_management_controller_for_poweredge_vrtx:-:*:*:*:*:*:*:*

History

27 Mar 2025, 16:08

Type Values Removed Values Added
CPE cpe:2.3:o:dell:chassis_management_controller_for_poweredge_fx2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:chassis_management_controller_for_poweredge_fx2:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:chassis_management_controller_for_poweredge_vrtx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:chassis_management_controller_for_poweredge_vrtx:-:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000297463/dsa-2025-123-security-update-for-dell-chassis-management-controller-firmware-for-dell-poweredge-fx2-and-vrtx-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000297463/dsa-2025-123-security-update-for-dell-chassis-management-controller-firmware-for-dell-poweredge-fx2-and-vrtx-vulnerabilities - Vendor Advisory
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Dell
Dell chassis Management Controller For Poweredge Vrtx Firmware
Dell chassis Management Controller For Poweredge Fx2 Firmware
Dell chassis Management Controller For Poweredge Vrtx
Dell chassis Management Controller For Poweredge Fx2

21 Mar 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-21 03:15

Updated : 2025-03-27 16:08


NVD link : CVE-2025-26336

Mitre link : CVE-2025-26336


JSON object : View

Products Affected

dell

  • chassis_management_controller_for_poweredge_fx2
  • chassis_management_controller_for_poweredge_vrtx_firmware
  • chassis_management_controller_for_poweredge_vrtx
  • chassis_management_controller_for_poweredge_fx2_firmware
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow