Impact
A heap‑based buffer overflow exists in Dell OpenManage Server Administrator versions prior to 11.1.0.3. The flaw allows a high privileged attacker with remote access to trigger an overrun of heap memory, leading to arbitrary code execution on the target system. The weakness corresponds to CWE‑122 and can compromise confidentiality, integrity, and availability of the affected host.
Affected Systems
The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows (Patch), RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04, when the installed version is older than 11.1.0.3.
Risk and Exploitability
With a CVSS score of 7.2, this vulnerability represents a high‑severity risk. No EPSS score has been published, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation may be limited but still possible. The likely attack vector is a remote network connection to the OpenManage service, and the attacker requires elevated privileges to trigger the overflow and execute arbitrary code.
OpenCVE Enrichment