Impact
Dell OpenManage Enterprise contains an improper privilege management flaw that can allow a high‑privileged attacker who already has remote access to elevate their privileges. The vulnerability is a classic example of CWE‑269 and, if exploited, would let the attacker gain more authority within the system than intended, potentially leading to full compromise of the managed infrastructure.
Affected Systems
The affected system is Dell OpenManage Enterprise for all versions released prior to 4.7.0. Any instance of this software that has not been updated to 4.7.0 or later is susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of 0.00316 (less than 1%) indicates a very low probability of exploitation. The lack of a KEV listing suggests no known active exploitation at this time. The likely attack vector is a remote high‑privileged attacker, inferred because the description states remote access is required and the attacker must possess high privileges to successfully abuse the flaw.
OpenCVE Enrichment