Database/Firmware, BMC & network fabric
Dell OMSA: improper privilege management lets a low-privileged remote user tamper with the node
Impact
A user who already holds a low-privileged OMSA account can act beyond that role, which Dell describes as information tampering and unauthorized access with high integrity and availability impact. On a fleet where OMSA credentials are handed to junior operators or to monitoring integrations, this collapses the distinction between read-only hardware monitoring and the ability to change hardware settings or take a node down. Recovery on a GPU node is expensive because the node has to be drained before it can be inspected or rebuilt.
Who can reach it
Network access to OMSA with any low-privileged OMSA account.
What to do
Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services. In the meantime review who holds non-admin OMSA accounts and whether service integrations need them at all.
References
Related entries
- Dell OMSA: missing authentication on a critical function lets an unauthenticated attacker execute codeCVE-2026-81475 · Dell OpenManage Server Administrator (managed node web/agent service)High
- Dell OMSA: unauthenticated OS command injection gives remote execution on the managed nodeCVE-2026-81476 · Dell OpenManage Server Administrator (managed node service, OS command handling)High
- Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agentCVE-2026-81478 · Dell OpenManage Server Administrator (hard-coded cryptographic key)High
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-004-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-010-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integratedCVE-2021-21505 · Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.