Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Published: 2026-09-17
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap‑based buffer overflow exists in Dell OpenManage Server Administrator versions prior to 11.1.0.3. The flaw allows a high privileged attacker with remote access to trigger an overrun of heap memory, leading to arbitrary code execution on the target system. The weakness corresponds to CWE‑122 and can compromise confidentiality, integrity, and availability of the affected host.

Affected Systems

The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows (Patch), RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04, when the installed version is older than 11.1.0.3.

Risk and Exploitability

With a CVSS score of 7.2, this vulnerability represents a high‑severity risk. No EPSS score has been published, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation may be limited but still possible. The likely attack vector is a remote network connection to the OpenManage service, and the attacker requires elevated privileges to trigger the overflow and execute arbitrary code.

Generated by OpenCVE AI on September 17, 2026 at 23:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Dell OpenManage Server Administrator patch (version 11.1.0.3 or newer) to eliminate the heap buffer overflow.
  • Limit remote access to the OpenManage service to authenticated administrators only, enforcing strong authentication and network segmentation.
  • Enable logging and monitoring of the OpenManage service to detect abnormal activity and potential exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Heap-based Buffer Overflow in Dell OpenManage Server Administrator Allows Remote Code Execution

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:55:41.222Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81477

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:41.584Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.710

Modified: 2026-10-06T15:21:58.763

Link: CVE-2026-81477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:40Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow