Database/Firmware, BMC & network fabric
Dell OpenManage Enterprise: path traversal exposes information to a low-privileged remote user
Impact
A pathname supplied to OpenManage Enterprise is not properly confined to its intended directory, letting a remote low-privileged account read data it should not. Dell states the impact as information exposure and does not name the files reachable, so treat the blast radius as unquantified rather than assuming the whole filesystem. The concern is the appliance's role: OME is the console that inventories and manages the iDRACs of every GPU server, and material recovered from it feeds directly into access on the out-of-band network. Confidentiality only per the scored vector.
Who can reach it
A remote attacker with a low-privileged OpenManage Enterprise account, reaching the OME console over the network. Authentication is required; no user interaction.
What to do
Update OpenManage Enterprise to 4.7.0 or later per Dell DSA-2026-359 — the same release that fixes CVE-2026-70423, so patch both together. The window is a restart of the OME appliance only; managed GPU servers are unaffected and need no drain, reboot or firmware flash. Keep the OME console restricted to the management VLAN and review low-privileged account holders.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.