GPU VulnDB

Database/Control plane, storage & DevOps

Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executes

CVE-2024-45766Control plane, storage & DevOpscurated

Impact

A low-privileged remote user injects code into OME and executes it. OME manages iDRACs fleet-wide, so code execution there means credentialed access to every BMC it manages.

Who can reach it

Authenticated low-privilege user of the OME web console, with interaction.

What to do

Upgrade OME past 4.1. Application upgrade with a service restart. Treat OME as tier-0: it holds fleet-wide BMC credentials, so compromise there is equivalent to compromising every server it manages.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.