Impact
Dell OpenManage Enterprise contains an improper neutralization of special elements used in an OS command, known as OS Command Injection. A high privileged attacker with remote access can trigger the vulnerability to execute arbitrary commands on the host, compromising confidentiality, integrity, and availability. The flaw is classified under CWE-78.
Affected Systems
The affected product is Dell OpenManage Enterprise, with any version prior to 4.7.0. The vulnerability appears in deployments that expose remote management interfaces to high privileged users, across all supported operating system platforms that run the software.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. The exploitation probability is unknown due to missing EPSS data, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, as the vulnerability requires remote access to the management console by a high privileged user. Attackers who meet these conditions could gain command execution privileges without additional authentication or local access.
OpenCVE Enrichment