Impact
The vulnerability is a heap‑based buffer overflow that can be triggered by writing beyond a memory boundary during a management command. This flaw permits a low‑privileged local user to overwrite control data, potentially allowing the attacker to execute arbitrary code with higher privileges. The impact is that an attacker who gains local access can elevate privileges on the affected machine, compromising the confidentiality, integrity, or availability of the system.
Affected Systems
The flaw affects Dell OpenManage Server Administrator Managed Node for Windows and for various Linux distributions, including RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04, in versions prior to 11.1.0.3. Dell publishes a security update that addresses the vulnerability, shipping under the identifier DSA‑2026‑403.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must have local, low‑privileged access, the attack vector is limited and the exploitation would require the attacker to be on the system. Nonetheless, the combination of a buffer overflow and privilege escalation is still considered a serious security risk, especially in environments where local administrators cannot be fully trusted.
OpenCVE Enrichment