Database/Firmware, BMC & network fabric
Dell OMSA: CSRF in the server management web interface can lead to remote execution
Impact
OMSA is the in-band server management agent fleets use to read hardware health and change platform settings. An unauthenticated attacker who can get an administrator's browser to load a crafted page can drive OMSA actions as that administrator, and Dell states the outcome can reach remote execution. On a GPU fleet that means platform-level changes or command execution on the host under the management agent's privileges, against the same nodes that are expensive to drain. Exploitation needs an admin to visit attacker content while authenticated to OMSA, which is the normal pattern for operators who keep the OMSA console open.
Who can reach it
Remote and unauthenticated as far as the attacker is concerned, but requires user interaction: an administrator with an active OMSA session must load the attacker's link or page. Reachability depends on whether OMSA's web port is exposed to networks where admins browse.
What to do
Upgrade OMSA to 11.1.0.3 or later per DSA-2026-403 on every managed node, including the Windows patch package and the RHEL 8.10/9.4, SLES 15 and Ubuntu 22.04 managed-node builds. This is an agent package update and service restart, not a firmware flash or reboot. Until then, keep the OMSA web interface off general-purpose networks and avoid browsing elsewhere from an authenticated OMSA session.
References
Related entries
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
- APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowCVE-2021-22815 · APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soCVE-2021-45925 · AMI MegaRAC SPx 12 / SPx 13 (BMC login)Medium
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: The IOMMU mishandles invalid nested page tableCVE-2023-20582 · AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checksMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.