Database/Firmware, BMC & network fabric
Dell OMSA: externally controlled class selection bypasses a protection mechanism
Impact
OMSA selects classes or code to load based on input an unauthenticated attacker controls, which Dell reports as a protection-mechanism bypass with low impact across confidentiality, integrity and availability. Unsafe reflection is usually a stepping stone rather than the whole attack - it is the piece that defeats a check standing in front of the other OMSA flaws fixed in the same advisory. Treat it as part of the same patch decision rather than something to weigh alone.
Who can reach it
Network access to the OMSA service on a managed node. No authentication required.
What to do
Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services; the same package fixes the other DSA-2026-403 issues.
References
Related entries
- Dell OMSA: local low-privileged user reads sensitive information beyond the agent's scopeCVE-2026-80356 · Dell OpenManage Server Administrator (sensitive information exposure)High
- Dell OMSA: hard-coded credentials give an unauthenticated remote attacker accessCVE-2026-81440 · Dell OpenManage Server Administrator (hard-coded credentials)High
- AMD SEV / SEV-ES - missing nested page table protection: SEV and SEV-ES do not protect the nested page tables, so aCVE-2020-12967 · AMD SEV / SEV-ES - missing nested page table protectionHigh
- ArubaOS GRUB2 implementation (secure boot): Two flaws in ArubaOS's GRUB2 implementation allow secure bootCVE-2020-24637 · ArubaOS GRUB2 implementation (secure boot)High
- Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation servers: An attacker with administrative reachCVE-2020-26122 · Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation serversHigh
- AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: A malicious hypervisor can rearrangeCVE-2021-26311 · AMD SEV / SEV-ES - guest address space rearrangement undetected by attestationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.