Impact
Dell OpenManage Enterprise contains a server‑side request forgery flaw that does not require authentication. An attacker who can reach the web interface can cause the server to issue arbitrary outgoing requests, potentially revealing internal network information or data that should remain private. This weakness is categorized as CWE‑918.
Affected Systems
All Dell OpenManage Enterprise installations with a major version earlier than 4.7.0 are vulnerable. The affected product is Dell OpenManage Enterprise, versions prior to 4.7.0.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 flags the vulnerability as high severity, reflecting the confidentiality impact of exposed data. EPSS information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote network access to the OpenManage web service, but no credentials are needed, making the attack vector straightforward for an attacker who can reach the target.
OpenCVE Enrichment