Database/Firmware, BMC & network fabric
Dell OMSA: missing authentication on a critical function lets a local user crash the management agent
Impact
OMSA is the in-band hardware management agent operators install on Dell PowerEdge nodes to read thermals, PSU state, RAID status and to drive out-of-band inventory. A local actor can invoke a critical OMSA function without authenticating and take the agent down. The record describes availability impact only - no confidentiality or integrity loss, and no code execution. On a GPU node the practical cost is blind hardware telemetry: fan, PSU and storage health stop reporting for that host, which matters most on fleets that gate drain/repair decisions on OMSA data rather than on the BMC directly.
Who can reach it
Local access to the node running the OMSA managed-node service. The record states the attacker is unauthenticated with local access, i.e. no OMSA credentials are needed once code runs on the host. Not reachable from the network per the CVSS vector (AV:L).
What to do
Upgrade the OMSA managed-node package to 11.1.0.3 or later per Dell DSA-2026-403. This is a userspace agent update: install the new package and restart the OMSA services (dsm_sa_datamgrd / DSM SA Data Manager on Windows). No firmware flash and no host reboot is called for in the advisory, so nodes do not need to be drained for the patch itself, though the monitoring agent is briefly unavailable during the restart.
References
Related entries
- Dell OMSA: partial string comparison flaw lets a low-privileged local user cause a denial of serviceCVE-2026-81479 · Dell OpenManage Server Administrator (OMSA) managed-node agentMedium
- Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial portCVE-2019-14456 · Opengear console server (serial port logging)Medium
- AMD Secure Processor bootloader - SPIROM upgrade path: An attacker who can drive the SPIROM upgrade path can passCVE-2025-48515 · AMD Secure Processor bootloader - SPIROM upgrade pathMedium
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSCVE-2025-7623 · Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-FMedium
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.