Impact
An unauthenticated attacker with remote access to the Dell OpenManage Server Administrator Web interface can exploit a Server‑Side Request Forgery (SSRF) flaw present in versions prior to 11.1.0.3. The flaw allows the attacker to instruct the OMAd service to fetch arbitrary URLs, which can be internal or external. This capability can be used to enumerate internal network services, exfiltrate sensitive information, or potentially trigger internal vulnerabilities, impacting confidentiality and integrity of the managed systems.
Affected Systems
All Dell OpenManage Server Administrator Managed Node installations running Windows, RHEL 8.10, RHEL 9.4, SLES 15, or Ubuntu 22.04 that use a version earlier than 11.1.0.3 are affected. Any deployment of the Managed Node component exposed to remote traffic and lacking authentication protection falls within this scope.
Risk and Exploitability
The CVSS score of 7.4 classifies the issue as high severity. Because the vulnerability is unauthenticated and the exploitation is server‑side, the primary attack vector is network based. Exploit code would be simple once a session is established, but no public exploitation data is currently reported and the vulnerability is not listed in the CISA KEV catalog. The absence of an EPSS score makes precise likelihood assessment difficult, yet the high CVSS suggests a meaningful risk if the interface is reachable from untrusted networks.
OpenCVE Enrichment