GPU VulnDB

Database/Control plane, storage & DevOps

Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway plugin

CVSS 8.8CVE-2024-24909Control plane, storage & DevOpscurated

Impact

The OMIMSWAC gateway plugin is how operators manage PowerEdge hardware - firmware updates, inventory, cluster-aware updating - from a Windows Admin Center gateway. An authenticated remote user can run arbitrary code and escalate privileges on the gateway. A WAC gateway typically holds credentials for, and network reach to, every server and iDRAC it manages, so code execution there is a pivot into the hardware management plane of the whole fleet rather than a single-host compromise. Dell rates it high severity and recommends upgrading at the earliest opportunity.

Who can reach it

Any authenticated user of the Windows Admin Center gateway running the Dell plugin; network-reachable, low privileges needed (AV:N/PR:L).

What to do

Update the Dell OpenManage Integration with Microsoft Windows Admin Center extension on the WAC gateway per DSA-2024-084; the extension restarts as part of the update and no managed-node downtime is involved. Restrict who can log in to the WAC gateway in the meantime - the flaw requires an account, so account hygiene is a real mitigation here.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.