Database/Firmware, BMC & network fabric
Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote user
Impact
OpenManage Enterprise before 4.7.0 fails to neutralize special elements in a SQL command, and Dell states a low-privileged remote attacker could exploit it, leading to script injection. OME is the console that inventories, configures and firmware-updates an entire iDRAC fleet, so its database holds the credentials and the reach to touch every server in the hall — a low-privileged account gaining read access there is a foothold into out-of-band management, which sits on a network most tenants never see and most operators trust implicitly. Dell's own scoring puts confidentiality high with limited availability impact and no integrity loss. The record does not describe a confirmed remote code execution path, only SQL injection leading to script injection.
Who can reach it
Remote attacker holding a low-privileged OpenManage Enterprise account, reaching the OME web interface — in most datacenters that means anyone with a console login on the management VLAN. Authentication is required.
What to do
Upgrade the OpenManage Enterprise appliance to 4.7.0 per Dell advisory DSA-2026-359; the appliance restarts, which takes the management console offline briefly but does not touch the managed servers. Until the upgrade, confirm the OME interface is reachable only from the management network and review which accounts hold low-privileged console logins.
References
Related entries
- Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on theCVE-2026-68425 · Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad)High
- Arista EOS: malformed packets crash the IGMP snooping agent and flood multicast to the whole VLANCVE-2026-73462 · Arista EOS IGMP snooping agentHigh
- Arista EOS: crafted packet expires multicast forwarding state early, dropping multicast trafficCVE-2026-73468 · Arista EOS multicast forwarding stateHigh
- IBM Server Firmware: unauthenticated request crashes the ASMI management web serverCVE-2026-93306 · IBM Server Firmware (ASMI web interface)High
- HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9CVE-2019-11983 · HPE iLO 4 / iLO 5 (remote buffer overflow)High
- Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU): A buffer shared between SMM and non-SMM codeCVE-2022-32469 · Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.