Impact
Dell OpenManage Server Administrator, versions before 11.1.0.3, contain a stack‑based buffer overflow that permits a highly privileged attacker with remote access to execute arbitrary code on the managed node. The flaw originates from insufficient input validation, allowing an attacker to overwrite the return address of the service process. If exploited, the attacker effectively gains the privileges of the service and can take full control of the affected system.
Affected Systems
Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15 and Ubuntu 22.04 running any version earlier than 11.1.0.3 are affected. The vulnerability impacts all systems that use these components without the official update.
Risk and Exploitability
The CVSS score of 7.2 reflects high severity. No KEV listing is present and the EPSS score is unavailable, indicating no confirmed widespread exploitation yet, though the risk remains significant. A remote attacker with privileged access can trigger the stack‑based overflow and achieve code execution, thereby compromising the confidentiality, integrity, and availability of the managed node.
OpenCVE Enrichment