Dell System Update flaw exposes servers to remote code execution
Dell has alerted customers to a critical security flaw in its System Update tool for PowerEdge servers, which could allow remote attackers to run code as root by exploiting a path traversal vulnerability. Three additional vulnerabilities were also patched, including two that enable unauthorized remote code execution. Dell recommends updating to version 2.3.0.0 or later immediately, though there is no indication these flaws have been exploited yet.
- Critical vulnerability affects Dell System Update tool
- Attackers could gain root access on unpatched servers
- Multiple additional high-severity flaws also addressed
- No reports yet of active exploitation, but risk remains high
Sources covering this
In this story
More in Cybersecurity
ClingSTUN malware exploits IoT vulnerabilities as stealth proxy network
A new Linux malware, called ClingSTUN or Cling, is turning unpatched and vulnerable internet-facing IoT devices into remote-controlled…
CrowdStrike launches Falcon Data Security for SaaS in Microsoft 365
CrowdStrike has announced general availability of Falcon Data Security for SaaS, a new product that secures sensitive data within…
Meta fixed major security flaw in Muse AI before launch
Meta engineers identified and urgently fixed several security vulnerabilities in its Muse AI agent just weeks before launch, according…
Denmark population database breach exposes 8.8 million records
Denmark’s Central Population Register, which tracks personal details for all residents and citizens, suffered a data breach affecting…