Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-09-17
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions before 11.1.0.3 contain a broken or risky cryptographic algorithm that can be abused by an unauthenticated attacker with remote network access to reveal sensitive information. The weakness is classified under CWE‑327, which indicates the use of a weakened or insecure cryptographic method and raises the possibility of data exposure if the algorithm can be bypassed or its keys compromised.

Affected Systems

Affected products include Dell OpenManage Server Administrator Managed Node for Windows and for various Linux distributions – RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04 – when the installed version is older than 11.1.0.3. Stakeholders should verify the release version of the software in use; any instance running a version before the patched edition is potentially exposed.

Risk and Exploitability

The CVSS score of 3.7 indicates a low‑to‑moderate severity and the EPSS score is currently unavailable. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has yet been observed. However, an attacker who gains unauthenticated remote access could leverage the weak cryptographic implementation to extract confidential data. The attack requires only network connectivity to the device; no privileged local access is needed, making it relatively straightforward for a threat actor with network visibility.

Generated by OpenCVE AI on September 17, 2026 at 21:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Dell OpenManage Server Administrator update that includes version 11.1.0.3 or later, which replaces the vulnerable cryptographic algorithm.
  • If the patch cannot be applied immediately, limit the exposure of affected nodes by restricting remote network access, for example, by placing them behind a firewall or segmenting them in a dedicated VLAN.
  • Continuously monitor network traffic and system logs for anomalous activities that could indicate exploitation attempts of cryptographic weaknesses.

Generated by OpenCVE AI on September 17, 2026 at 21:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Risky Cryptographic Algorithm in Dell OpenManage Server Administrator Enables Remote Information Disclosure

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node (patch) For Windows
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node (patch) For Windows
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node (patch) For Windows Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T14:29:20.228Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81438

cve-icon Vulnrichment

Updated: 2026-09-17T14:29:14.769Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T11:17:02.833

Modified: 2026-10-01T17:08:56.340

Link: CVE-2026-81438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm