Impact
Dell OpenManage Server Administrator versions earlier than 11.1.0.3 contain a flaw that allows a low‑privileged attacker with local access to trigger a partial string comparison bug. When exploited, the vulnerability can cause the management service to crash, resulting in a denial of service for both the local host and any remote management sessions that rely on that service. The weakness is a classic partial string comparison failure, which can be hijacked to force a state change that terminates the process.
Affected Systems
The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All releases before 11.1.0.3 are impacted; any system running an earlier version should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.8 indicates a medium impact. No EPSS score is available, so the likelihood of exploitation is uncertain, but because the attacker only needs local low‑privileged access the attack can be launched from the local console or an unprivileged user account. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploits, yet the local privilege requirement makes a successful attack reasonably feasible. Systems that allow unauthenticated or low‑privileged users local console access are the highest risk.
OpenCVE Enrichment