Patch & vulnerability status
Dell Inc.
Dell iDRAC Service Module 5.2.0.0
Latest tracked version 5.2.0.0. Release status, tracked CVEs, and automated cross-platform patching for Dell iDRAC Service Module.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 5.2.0.0 | 9 | 2024-08-26 |
Known vulnerabilities (CVEs) in Dell iDRAC Service Module
Lavawall tracks 9 published CVEs affecting Dell iDRAC Service Module, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2025-38743 | 2025-08-21 19:15:42 | HIGH (8) | Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | LOCAL |
| CVE-2025-38742 | 2025-08-21 19:15:41 | MEDIUM (5) | Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | LOCAL |
| CVE-2024-38490 | 2024-08-01 08:15:03 | MEDIUM (6) | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | LOCAL |
| CVE-2024-38489 | 2024-08-01 08:15:03 | MEDIUM (4) | Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event. | LOCAL |
| CVE-2024-38481 | 2024-08-01 08:15:03 | MEDIUM (5) | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | LOCAL |
| CVE-2024-25948 | 2024-08-01 08:15:02 | MEDIUM (5) | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | LOCAL |
| CVE-2024-25947 | 2024-08-01 07:15:02 | MEDIUM (5) | Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. | LOCAL |
| CVE-2024-22428 | 2024-01-16 04:15:08 | HIGH (8) | Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest opportunity. | LOCAL |
| CVE-2018-11053 | 2018-06-26 22:29:00 | MEDIUM (7) | Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A malicious low privileged operating system user or process could modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content. | NETWORK |
Why keeping Dell iDRAC Service Module patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Dell iDRAC Service Module release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Dell iDRAC Service Module
Lavawall® watches Dell iDRAC Service Module releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Dell iDRAC Service Module, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Dell iDRAC Service Module at version 5.2.0.0 (last checked 2024-08-26). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 9 CVEs for Dell iDRAC Service Module and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Dell iDRAC Service Module updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Dell iDRAC Service Module through public information and proprietary statistical analysis, and can patch it automatically across your fleet.