← back
CVE-2025-22397

CVE-2025-22397

CVSS 6.7 MEDIUMEPSS 0.4%CWE-22
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.7EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
06 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →