Impact
Dell OpenManage Server Administrator versions before 11.1.0.3 contain a broken or risky cryptographic algorithm that can be abused by an unauthenticated attacker with remote network access to reveal sensitive information. The weakness is classified under CWE‑327, which indicates the use of a weakened or insecure cryptographic method and raises the possibility of data exposure if the algorithm can be bypassed or its keys compromised.
Affected Systems
Affected products include Dell OpenManage Server Administrator Managed Node for Windows and for various Linux distributions – RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04 – when the installed version is older than 11.1.0.3. Stakeholders should verify the release version of the software in use; any instance running a version before the patched edition is potentially exposed.
Risk and Exploitability
The CVSS score of 3.7 indicates a low‑to‑moderate severity and the EPSS score is currently unavailable. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has yet been observed. However, an attacker who gains unauthenticated remote access could leverage the weak cryptographic implementation to extract confidential data. The attack requires only network connectivity to the device; no privileged local access is needed, making it relatively straightforward for a threat actor with network visibility.
OpenCVE Enrichment