CVE-2025-22397
CVE-2025-22397
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.7EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
06 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H
Affected products
Dell · Integrated Dell Remote Access Controller 10 17G versionDell · Integrated Dell Remote Access Controller 9 14G VersionsDell · Integrated Dell Remote Access Controller 9 15G and 16G versionsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →