Database/Control plane, storage & DevOps
Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway plugin
Impact
The OMIMSWAC gateway plugin is how operators manage PowerEdge hardware - firmware updates, inventory, cluster-aware updating - from a Windows Admin Center gateway. An authenticated remote user can run arbitrary code and escalate privileges on the gateway. A WAC gateway typically holds credentials for, and network reach to, every server and iDRAC it manages, so code execution there is a pivot into the hardware management plane of the whole fleet rather than a single-host compromise. Dell rates it high severity and recommends upgrading at the earliest opportunity.
Who can reach it
Any authenticated user of the Windows Admin Center gateway running the Dell plugin; network-reachable, low privileges needed (AV:N/PR:L).
What to do
Update the Dell OpenManage Integration with Microsoft Windows Admin Center extension on the WAC gateway per DSA-2024-084; the extension restarts as part of the update and no managed-node downtime is involved. Restrict who can log in to the WAC gateway in the meantime - the flaw requires an account, so account hygiene is a real mitigation here.
References
Related entries
- A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestViewCVE-2024-30368 · A10 Thunder ADC (CsrRequestView)High
- CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesCVE-2024-31856 · CyberPower PowerPanel MQTT message handlingHigh
- AMD Graphics Driver - crafted pointer leading to arbitrary code execution: Improper input validation in the AMDCVE-2024-36324 · AMD Graphics Driver - crafted pointer leading to arbitrary code executionHigh
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarCVE-2024-43044 · JenkinsHigh
- Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload featureCVE-2024-50627 · Digi ConnectPort LTS (before 1.4.12)High
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedCVE-2024-5948 · Deep Sea Electronics DSE855 generator communications gatewayHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.