Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Published: 2026-09-17
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

An improper certificate validation flaw exists in Dell OpenManage Server Administrator versions older than 11.1.0.3. The flaw allows a remote actor without prior authentication, who has access to the same local network, to supply a forged or otherwise untrusted certificate to a service. If accepted, the attacker can read or alter confidential management data, leading to information disclosure and tampering.

Affected Systems

The vulnerability affects Dell OpenManage Server Administrator Managed Node (Patch) for Windows, Dell OpenManage Server Administrator Managed Node for RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All versions preceding 11.1.0.3 are susceptible. Network adjacency is required, meaning the attacker must be on a network segment that can reach the OMSA management console.

Risk and Exploitability

With a CVSS score of 6.8 the flaw represents a medium severity risk. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, implying no widespread public exploitation is documented. However, because the flaw permits bypassing authentication via certificate trust, an attacker on an adjacent network could potentially harvest sensitive configuration information or tamper with system settings. Defending against this threat requires upgrading to the patched release and reinforcing network segmentation.

Generated by OpenCVE AI on September 17, 2026 at 20:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dell OpenManage Server Administrator Managed Node to version 11.1.0.3 or newer, which resolves the improper certificate validation flaw.
  • Reconfigure OMSA network interfaces to enforce strict TLS certificate verification for all management connections.
  • Segment or firewall adjacent network segments to restrict unauthenticated access to the OMSA services.

Generated by OpenCVE AI on September 17, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Dell OpenManage Server Administrator Leading to Information Disclosure

Thu, 17 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:56:02.106Z

Reserved: 2026-08-26T20:04:54.730Z

Link: CVE-2026-81447

cve-icon Vulnrichment

Updated: 2026-09-17T17:15:09.794Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T15:16:52.697

Modified: 2026-10-06T15:37:29.950

Link: CVE-2026-81447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:05Z

Weaknesses
  • CWE-295

    Improper Certificate Validation