Dell iDRAC9/10 < 7.20.30.50/1.20.60.50: Remanent Memory Read (Info Disclosure)
CVE-2026-70412 Published on August 17, 2026
Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Vulnerability Analysis
CVE-2026-70412 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
Remanent Data Readable after Memory Erase
Confidential information stored in memory circuits is readable or recoverable after being cleared or erased.
Products Associated with CVE-2026-70412
Want to know whenever a new CVE is published for Dell Idrac9? stack.watch will email you.
Affected Versions
Dell iDRAC9:- Before 7.20.30.50 or later is affected.
- Before 1.20.60.50 or later is affected.