Impact
Dell OpenManage Server Administrator versions before 11.1.0.2 contain a relative path traversal flaw (CWE-23). A low‑privileged attacker who can reach the OMSA network service may traverse directories outside the intended filesystem boundaries, potentially reading or modifying system files. This threatens both confidentiality and integrity of the host system.
Affected Systems
Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, and SLES 15 are affected when installed with a release earlier than 11.1.0.2, as documented in Dell’s security bulletin.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploitation yet. Nonetheless, the flaw is remotely exploitable by an adversary with only low privileges, providing filesystem access if the OMSA service is reachable. Organizations with OMSA exposed to untrusted networks face a moderate to high risk and should address it promptly.
OpenCVE Enrichment