Impact
Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain a vulnerability that allows externally controlled input to select classes or code. An unauthenticated attacker with remote access can exploit this flaw, enabling the attacker to bypass built‑in protection mechanisms. The advisory states the impact as a protection mechanism bypass; it does not explicitly confirm code execution or system compromise, so the full extent of damage must be assessed by the affected organization.
Affected Systems
The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows, for RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. Any deployment running a version earlier than 11.1.0.3 is susceptible. Users should review the installed version and update accordingly.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation documented yet. Because the flaw can be triggered by an unauthenticated remote attacker with direct access to the service, and it involves unsafe reflection, it is inferred that this flaw could allow malicious code injection or bypass of runtime protections, potentially leading to further compromise depending on system configuration and exposure.
OpenCVE Enrichment