Impact
The vulnerability is a Cross‑Site Request Forgery (CWE‑352) affecting Dell OpenManage Server Administrator prior to version 11.1.0.3. An attacker who can reach the web interface without authentication can send a forged request that is accepted by the system, which may result in the execution of arbitrary commands on the host, effectively allowing remote code execution.
Affected Systems
Affected products include Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All releases before 11.1.0.3 are vulnerable, and the flaw applies across all supported operating systems for the managed node deployment of the product.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity; the EPSS score is not available, suggesting limited published exploitation data. The vulnerability is not listed in CISA KEV. An attacker with remote access can exploit the CSRF vulnerability without needing user interaction or credentials, making it a low‑barrier risk for systems exposed to the internet.
OpenCVE Enrichment