Impact
The vulnerability arises from the use of a hard‑coded cryptographic key in Dell OpenManage Server Administrator prior to version 11.1.0.3. This flaw permits an unauthenticated remote attacker to bypass normal authentication and obtain unauthorized access to the system’s management interface, compromising confidentiality and integrity of data. The weakness is classified as CWE‑321, indicating improper key management.
Affected Systems
This issue impacts Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All releases before 11.1.0.3 are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 classifies the vulnerability as High. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker with remote network access can exploit the hard‑coded key to gain unauthorized access. Because the flaw requires only remote connectivity and no special privileges, the risk remains significant for exposed deployments.
OpenCVE Enrichment