Database/Firmware, BMC & network fabric
Dell OMSA: hard-coded credentials give an unauthenticated remote attacker access
Impact
Credentials shipped in the product let an unauthenticated network attacker log in to the hardware management agent on any node running an affected OMSA version. Impact is rated low across confidentiality, integrity and availability, so this is a foothold in the management plane rather than immediate node takeover - but it is the same credential on every node, so it scales across the whole fleet without any additional work for the attacker. This is distinct from CVE-2026-81478, which is a hard-coded cryptographic key rather than a credential.
Who can reach it
Network access to the OMSA service. No authentication required.
What to do
Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Changing local account passwords does not remove credentials compiled into the shipped version.
References
Related entries
- AMD SEV / SEV-ES - missing nested page table protection: SEV and SEV-ES do not protect the nested page tables, so aCVE-2020-12967 · AMD SEV / SEV-ES - missing nested page table protectionHigh
- ArubaOS GRUB2 implementation (secure boot): Two flaws in ArubaOS's GRUB2 implementation allow secure bootCVE-2020-24637 · ArubaOS GRUB2 implementation (secure boot)High
- Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation servers: An attacker with administrative reachCVE-2020-26122 · Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation serversHigh
- AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: A malicious hypervisor can rearrangeCVE-2021-26311 · AMD SEV / SEV-ES - guest address space rearrangement undetected by attestationHigh
- Intel TXT SINIT Authenticated Code Module for some Intel processors: Improper initialization in the SINIT ACMCVE-2022-30704 · Intel TXT SINIT Authenticated Code Module for some Intel processorsHigh
- Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left withCVE-2022-33196 · Intel Xeon memory controller configuration (with SGX)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.