Impact
The vulnerability is an improper neutralization of special elements used in an OS command, allowing an attacker to inject and execute arbitrary system commands. Because the flaw can be exploited by anyone with remote access and does not require authentication, it potentially leads to full system compromise and loss of confidentiality, integrity, and availability.
Affected Systems
Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All versions before 11.1.0.3 are affected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network access to the OpenManage interface, with no authentication required to trigger the command injection.
OpenCVE Enrichment