Database/Control plane, storage & DevOps
Dell OpenManage Enterprise (credential disclosure): A low-privileged local user obtains stored credentials from OME
CVSS 6.3CVE-2024-28961Control plane, storage & DevOpscurated
Impact
A low-privileged local user obtains stored credentials from OME, leading to elevated unauthorized access - in practice, the BMC credentials OME uses to manage the fleet.
Who can reach it
Local low-privilege access to the OME appliance (versions 4.0.0/4.0.1).
What to do
Apply the DSA-2024-184 update, then rotate the discovery/management credentials OME holds. The rotation matters more than the patch.
References
Related entries
- Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keysCVE-2026-19197 · Grafana (dashboard snapshot API)Medium
- CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskCVE-2026-49943 · CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching)Medium
- Jenkins: agent config update names its own target, letting one agent's configurer take over anotherCVE-2026-84651 · Jenkins controller (REST API and CLI agent configuration update)Medium
- Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exportersCVE-2022-46146 · Prometheus (exporter-toolkit)Medium
- OpenTelemetry eBPF Profiler: unprivileged process can stall the agent by mapping a FIFOCVE-2026-48496 · OpenTelemetry eBPF Profiler (ELF mapping file handling)Medium
- AMD TEE / ASP bootloader syscall input validation: Insufficient validation of syscall inputs in the AMD trustedCVE-2021-46759 · AMD TEE / ASP bootloader syscall input validationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.