Impact
Dell OpenManage Enterprise versions before 4.7.0 contain a flaw that allows an attacker with low privileges and remote access to inject operating system commands and execute them. The vulnerability is an improper neutralization of special elements in command strings, which can lead to arbitrary command execution and potentially full system compromise. According to the description, the attacker only needs remote access and does not require elevated privileges to trigger the exploit.
Affected Systems
The affected product is Dell OpenManage Enterprise, any installation running a version earlier than 4.7.0. All systems participating in the OpenManage Enterprise management network are susceptible, regardless of the specific deployment size.
Risk and Exploitability
The CVSS score of 8.8 categorizes this issue as high severity, and the EPSS score of 2% indicates a low but non-zero chance of exploitation, while the lack of KEV listing does not diminish the inherent risk. An attacker can exploit the vulnerability remotely over network services provided by OpenManage Enterprise, and the low prerequisite of a low‑privileged account means that many environments could be impacted. Once exploited, the attacker gains the ability to execute arbitrary OS commands, which can compromise confidentiality, integrity, and availability of the affected infrastructure.
OpenCVE Enrichment