Database/Control plane, storage & DevOps
Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executes
CVSS 8.0CVE-2024-45766Control plane, storage & DevOpscurated
Impact
A low-privileged remote user injects code into OME and executes it. OME manages iDRACs fleet-wide, so code execution there means credentialed access to every BMC it manages.
Who can reach it
Authenticated low-privilege user of the OME web console, with interaction.
What to do
Upgrade OME past 4.1. Application upgrade with a service restart. Treat OME as tier-0: it holds fleet-wide BMC credentials, so compromise there is equivalent to compromising every server it manages.
References
Related entries
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyCVE-2025-68803 · Linux NFS server (nfsd, NFSv4 file creation ACL)High
- Lantronix Provisioning Manager: Provisioning Manager reads configuration files supplied by the network devicesCVE-2025-7766 · Lantronix Provisioning ManagerHigh
- Progress Kemp LoadMaster Multi Tenant: The Multi Tenant product line's REST API doesn't check whether a caller'sCVE-2026-59690 · Progress Kemp LoadMaster Multi TenantHigh
- Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSSCVE-2026-84665 · Jenkins SonarQube Scanner Plugin (dashboard link generation)High
- Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator toCVE-2026-92127 · Jenkins Script Security Plugin (classpath entry approval)High
- Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UICVE-2026-92134 · Jenkins Warnings Plugin (analysis results ID validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.