GPU VulnDB

Database/Control plane, storage & DevOps

Dell OpenManage Server Administrator (network-facing management service): OMSA is the in-band hardware management agent

CVSS 7.5CVE-2026-81438Control plane, storage & DevOpscurated

Impact

OMSA is the in-band hardware management agent operators install on PowerEdge compute nodes - including GPU nodes - to read sensor, storage and firmware state. Dell states that the use of a broken or risky cryptographic algorithm lets an attacker with remote network access and no credentials obtain information from the service. On a fleet where OMSA listens on a management or provisioning network, that is inventory and hardware-state disclosure across every node running the affected agent, and potentially material useful for a follow-on attack on the management plane. The advisory does not describe which data is exposed, so treat the scope as unspecified confidentiality loss rather than a known credential leak.

Who can reach it

Anyone who can reach the OMSA service over the network on an affected node. No authentication required (CVSS AV:N/PR:N).

What to do

Upgrade OMSA Managed Node to 11.1.0.3 or later per DSA-2026-403 (packages exist for RHEL 8.10/9.4, SLES 15, Ubuntu 22.04 and Windows); the agent services restart as part of the package upgrade, so no node reboot is called for in the advisory. Until then, restrict the OMSA listener to the management VLAN or stop the service on nodes that do not need it.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.