Impact
Dell OpenManage Server Administrator, versions preceding 11.1.0.3, has a vulnerability that permits an exposure of sensitive information to an unauthorized local actor. The flaw can be exploited by an attacker with low‑privileged local access, enabling them to view information they should not be able to see. The weakness is identified as a CWE-200 type flaw, which undermines confidentiality and could reveal configuration details or other sensitive data.
Affected Systems
The affected products are Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All installations running a version earlier than 11.1.0.3 are susceptible to this issue.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity scenario. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring low‑privileged attacker access; therefore, the primary risk is information disclosure from the managed node to an unprivileged user.
OpenCVE Enrichment