Impact
The Dell OpenManage Server Administrator software contains an Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) flaw in versions prior to 11.1.0.3. A low‑privileged attacker with remote access can exploit this to read or write arbitrary files on the system, granting filesystem access to the attacker.
Affected Systems
The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All installations running a version below 11.1.0.3 are impacted.
Risk and Exploitability
The CVSS score is 6.5, placing the risk in the medium range. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation is uncertain, but the remote attack vector and low privilege requirement mean that an attacker able to reach the OpenManage interface could execute the path traversal. Immediate patching is recommended to eliminate the exposure.
OpenCVE Enrichment