GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: missing authentication on a critical function lets a local user crash the management agent

CVSS 5.5CVE-2026-81441Firmware, BMC & network fabriccurated

Impact

OMSA is the in-band hardware management agent operators install on Dell PowerEdge nodes to read thermals, PSU state, RAID status and to drive out-of-band inventory. A local actor can invoke a critical OMSA function without authenticating and take the agent down. The record describes availability impact only - no confidentiality or integrity loss, and no code execution. On a GPU node the practical cost is blind hardware telemetry: fan, PSU and storage health stop reporting for that host, which matters most on fleets that gate drain/repair decisions on OMSA data rather than on the BMC directly.

Who can reach it

Local access to the node running the OMSA managed-node service. The record states the attacker is unauthenticated with local access, i.e. no OMSA credentials are needed once code runs on the host. Not reachable from the network per the CVSS vector (AV:L).

What to do

Upgrade the OMSA managed-node package to 11.1.0.3 or later per Dell DSA-2026-403. This is a userspace agent update: install the new package and restart the OMSA services (dsm_sa_datamgrd / DSM SA Data Manager on Windows). No firmware flash and no host reboot is called for in the advisory, so nodes do not need to be drained for the patch itself, though the monitoring agent is briefly unavailable during the restart.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.