Impact
An improper certificate validation flaw exists in Dell OpenManage Server Administrator versions older than 11.1.0.3. The flaw allows a remote actor without prior authentication, who has access to the same local network, to supply a forged or otherwise untrusted certificate to a service. If accepted, the attacker can read or alter confidential management data, leading to information disclosure and tampering.
Affected Systems
The vulnerability affects Dell OpenManage Server Administrator Managed Node (Patch) for Windows, Dell OpenManage Server Administrator Managed Node for RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All versions preceding 11.1.0.3 are susceptible. Network adjacency is required, meaning the attacker must be on a network segment that can reach the OMSA management console.
Risk and Exploitability
With a CVSS score of 6.8 the flaw represents a medium severity risk. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, implying no widespread public exploitation is documented. However, because the flaw permits bypassing authentication via certificate trust, an attacker on an adjacent network could potentially harvest sensitive configuration information or tamper with system settings. Defending against this threat requires upgrading to the patched release and reinforcing network segmentation.
OpenCVE Enrichment