Impact
Dell OpenManage Server Administrator versions earlier than 11.1.0.3 have a Missing Authentication for Critical Function vulnerability (CWE-306). An attacker who can reach the module over the network may invoke privileged functions without providing credentials, which can lead to full remote code execution on the host, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected products include Dell OpenManage Server Administrator Managed Node for Windows, for RHEL 8.10, for RHEL 9.4, for SLES 15, and for Ubuntu 22.04; all releases prior to 11.1.0.3 are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. The attack vector is inferred to be remote network access; an unauthenticated attacker can trigger the vulnerable function from outside the host, potentially executing arbitrary code under the context of the OMSA service.
OpenCVE Enrichment