Database/Control plane, storage & DevOps
Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS Accept
CVSS 8.8CVE-2025-36593Control plane, storage & DevOpscurated
Impact
An attacker on the local network forges a valid RADIUS Accept in response to a failed authentication - so a rejected login becomes an accepted one. This is the Blast-RADIUS protocol weakness landing in Dell's fabric management tool.
Who can reach it
Local network position between OMNI and the RADIUS server.
What to do
Upgrade OMNI to 3.8. Beyond the patch, the structural fix is running RADIUS over an authenticated transport (RADSEC/TLS) or moving fabric admin auth off RADIUS entirely.
References
Related entries
- Commvault Web Server: Remote authenticated attacker creates and executes webshellsCVE-2025-3928 · Commvault Web ServerHigh
- Linux iommu/amd - race while increasing host page table level: The AMD IOMMU host page table implementation supportsCVE-2025-39961 · Linux iommu/amd - race while increasing host page table levelHigh
- VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarmsCVE-2025-41225 · VMware vCenter Server (authenticated command execution via alarms)High
- N-able N-central: Improper input validationCVE-2025-8876 · N-able N-centralHigh
- Grafana: symlink escape in plugin archive extraction gives remote code execution as the Grafana processCVE-2026-15815 · Grafana OSS / Enterprise (plugin archive extraction)High
- Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): The RHOAI overlayCVE-2026-18951 · Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.