Database/Firmware, BMC & network fabric
Dell OMSA: local low-privileged user reads sensitive information beyond the agent's scope
Impact
A local low-privileged user on a node running OMSA can read information the agent should keep to itself, and Dell scores it with a scope change and high confidentiality impact - so what leaks is not confined to OMSA's own data. On a GPU host, anything OMSA holds about hardware management access is useful to an attacker who has a shell and wants the management plane next.
Who can reach it
Local shell on a managed node with any low-privileged account.
What to do
Upgrade OMSA to 11.1.0.3 or later and restart the OMSA services. If the leaked material turns out to include management credentials on your nodes, rotate them after patching; Dell's advisory does not say what is exposed.
References
Related entries
- Dell OMSA: hard-coded credentials give an unauthenticated remote attacker accessCVE-2026-81440 · Dell OpenManage Server Administrator (hard-coded credentials)High
- AMD SEV / SEV-ES - missing nested page table protection: SEV and SEV-ES do not protect the nested page tables, so aCVE-2020-12967 · AMD SEV / SEV-ES - missing nested page table protectionHigh
- ArubaOS GRUB2 implementation (secure boot): Two flaws in ArubaOS's GRUB2 implementation allow secure bootCVE-2020-24637 · ArubaOS GRUB2 implementation (secure boot)High
- Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation servers: An attacker with administrative reachCVE-2020-26122 · Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation serversHigh
- AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: A malicious hypervisor can rearrangeCVE-2021-26311 · AMD SEV / SEV-ES - guest address space rearrangement undetected by attestationHigh
- Intel TXT SINIT Authenticated Code Module for some Intel processors: Improper initialization in the SINIT ACMCVE-2022-30704 · Intel TXT SINIT Authenticated Code Module for some Intel processorsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.