Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized remote access
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the use of a hard‑coded cryptographic key in Dell OpenManage Server Administrator prior to version 11.1.0.3. This flaw permits an unauthenticated remote attacker to bypass normal authentication and obtain unauthorized access to the system’s management interface, compromising confidentiality and integrity of data. The weakness is classified as CWE‑321, indicating improper key management.

Affected Systems

This issue impacts Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All releases before 11.1.0.3 are vulnerable.

Risk and Exploitability

The CVSS score of 8.1 classifies the vulnerability as High. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker with remote network access can exploit the hard‑coded key to gain unauthorized access. Because the flaw requires only remote connectivity and no special privileges, the risk remains significant for exposed deployments.

Generated by OpenCVE AI on September 17, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Dell OpenManage Server Administrator update (version 11.1.0.3 or later) on all affected systems.
  • Restrict network access to OMSA Managed Node services using firewalls or network segmentation to limit exposure to unauthenticated remote connections.
  • Disable or remove any configuration that allows unauthenticated remote access to OMSA services.

Generated by OpenCVE AI on September 17, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Thu, 17 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Hard‑coded Cryptographic Key Enables Remote Unauthorized Access in Dell OpenManage Server Administrator

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-18T03:55:40.144Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81478

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:43.664Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.830

Modified: 2026-10-06T15:26:11.190

Link: CVE-2026-81478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:37Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key