Database/Firmware, BMC & network fabric
Dell OpenManage Enterprise: XML external entity processing exposes information to a low-privileged user
Impact
OpenManage Enterprise parses XML without restricting external entity references, and Dell characterises the result as information exposure to a remote low-privileged attacker; the advisory does not state what can be read, so do not assume full arbitrary file read. What makes it worth a window is where OME sits: it is the fleet console for iDRACs, holding server inventory, firmware baselines and credentialed access to the out-of-band path of every GPU chassis. Anything an operator-tier account can pull out of that appliance shortens the route to the management network that can power-cycle or reflash nodes. Confidentiality only per the scored vector — no integrity or availability impact claimed.
Who can reach it
A remote attacker holding a low-privileged OpenManage Enterprise account, reaching the OME console over the network. Authentication is required. In a correctly segmented datacenter that means someone already on the management VLAN or with valid OME credentials.
What to do
Update OpenManage Enterprise to 4.7.0 or later per Dell DSA-2026-359. This is an appliance-side update: the OME console is unavailable while it restarts, but managed servers keep running and no GPU node needs to be drained, rebooted or reflashed. Both this and CVE-2026-70424 are fixed by the same release, so do them in one window. Independently, confirm the OME console is not reachable outside the management VLAN and review who holds low-privileged OME accounts.
References
Related entries
- Dell OpenManage Enterprise: path traversal exposes information to a low-privileged remote userCVE-2026-70424 · Dell OpenManage Enterprise (path traversal in a restricted-directory check)Medium
- Arista EOS: DHCP relay forwards replies from unconfigured servers, allowing client config spoofingCVE-2026-73437 · Arista EOS DHCP relay (helper-address source validation)Medium
- Dell OMSA: authenticated path traversal lets a low-privileged user read files off the nodeCVE-2026-81453 · Dell OpenManage Server Administrator (path traversal, authenticated)Medium
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: RNICs cacheNCVD-2019-003-rnic-on-board-sram-metadata-cach · RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NICMedium
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: RNICs cacheNCVD-2019-006-rnic-on-board-sram-metadata-cach · RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NICMedium
- RoCEv2 congestion control - DCQCN, ECN marking and Congestion Notification Packets: DCQCN reacts to ECN marks by havingNCVD-2022-003-rocev2-congestion-control-dcqcn · RoCEv2 congestion control - DCQCN, ECN marking and Congestion Notification PacketsMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.