Impact
The vulnerability is a Server‑Side Request Forgery flaw in Dell OpenManage Server Administrator versions before 11.1.0.3. An attacker with low privileged remote access can craft requests that force the server to resolve arbitrary URLs, potentially leaking internal information or enabling further attacks against the internal network.
Affected Systems
The flaw affects all Dell OpenManage Server Administrator Managed Node deployments for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04 that are running a version earlier than 11.1.0.3.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. Based on the description, it is inferred that a low privileged attacker can trigger the SSRF over the network interface exposed by OMSA, and that the risk depends on the exposure of the OMSA management console and the internal resources reachable from it.
OpenCVE Enrichment