Impact
An improper limitation of a pathname to a restricted directory exists in Dell OpenManage Server Administrator versions prior to 11.1.0.3. The flaw, also known as path traversal, allows a remote attacker who does not need to authenticate to read or write files outside the intended directory. If exploited, the attacker can gain access to sensitive configuration files or system binaries with the permissions of the OpenManage Server Administrator process, leading to potential data disclosure.
Affected Systems
Dell OpenManage Server Administrator Managed Node for Windows, RHEL 8.10, RHEL 9.4, SLES 15, and Ubuntu 22.04 are affected, specifically any installation of the product with a version earlier than 11.1.0.3.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the attack vector is remote with no authentication required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high impact score and the nature of the flaw suggest that attackers could readily target systems without credentials and read restricted files.
OpenCVE Enrichment