Impact
Dell OpenManage Server Administrator versions prior to 11.1.0.3 contain a Use of Hard‑coded Credentials flaw. The application stores default credentials that can be used by an attacker to gain unauthorized access. An attacker who can reach the service remotely could authenticate with these predefined credentials, leading to unauthorized control over the server management functions.
Affected Systems
Affected product is Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All assets running any of these Linux or Windows distributions with OMSA prior to release 11.1.0.3 are vulnerable. Dell recommends updating to the security‑fixed version or later.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time. An unauthenticated attacker with remote access; the attacker can reach the management service over the network. The presence of hard‑coded credentials removes the requirement for legitimate authentication, making the exploit straightforward once network reachability is achieved.
OpenCVE Enrichment