Description
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
Published: 2026-09-17
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Dell OpenManage Server Administrator versions earlier than 11.1.0.3 contain a flaw that allows a low‑privileged attacker with local access to trigger a partial string comparison bug. When exploited, the vulnerability can cause the management service to crash, resulting in a denial of service for both the local host and any remote management sessions that rely on that service. The weakness is a classic partial string comparison failure, which can be hijacked to force a state change that terminates the process.

Affected Systems

The vulnerability affects Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04. All releases before 11.1.0.3 are impacted; any system running an earlier version should be considered vulnerable.

Risk and Exploitability

The CVSS score of 5.8 indicates a medium impact. No EPSS score is available, so the likelihood of exploitation is uncertain, but because the attacker only needs local low‑privileged access the attack can be launched from the local console or an unprivileged user account. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploits, yet the local privilege requirement makes a successful attack reasonably feasible. Systems that allow unauthenticated or low‑privileged users local console access are the highest risk.

Generated by OpenCVE AI on September 18, 2026 at 06:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Dell OpenManage Server Administrator update for version 11.1.0.3 or newer according to the Dell DSA‑2026‑403 advisory.
  • If an immediate update is not possible, disable local access to the management console or restrict it to highly privileged accounts only.
  • After applying the update or restriction, restart the Dell OpenManage service to ensure a clean state.

Generated by OpenCVE AI on September 18, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell openmanage Server Administrator
CPEs cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Vendors & Products Dell openmanage Server Administrator

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows
Vendors & Products Dell
Dell dell Openmanage Server Administrator Managed Node For Rhel 8.10
Dell dell Openmanage Server Administrator Managed Node For Rhel 9.4
Dell dell Openmanage Server Administrator Managed Node For Sles 15
Dell dell Openmanage Server Administrator Managed Node For Ubuntu 22.04
Dell openmanage Server Administrator Managed Node (patch) For Windows

Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Partial String Comparison Vulnerability Allowing Local Denial of Service

Thu, 17 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
Weaknesses CWE-187
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Dell Dell Openmanage Server Administrator Managed Node For Rhel 8.10 Dell Openmanage Server Administrator Managed Node For Rhel 9.4 Dell Openmanage Server Administrator Managed Node For Sles 15 Dell Openmanage Server Administrator Managed Node For Ubuntu 22.04 Openmanage Server Administrator Openmanage Server Administrator Managed Node (patch) For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T12:03:08.264Z

Reserved: 2026-08-26T20:04:54.733Z

Link: CVE-2026-81479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T12:18:27.950

Modified: 2026-10-02T14:29:12.370

Link: CVE-2026-81479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-187

    Partial String Comparison