Database/Firmware, BMC & network fabric
Dell OMSA: authenticated SSRF lets a low-privileged user reach systems behind the agent
Impact
A low-privileged OMSA account can make the agent issue requests to systems it chooses, with a scope change and low confidentiality and integrity impact. The value to an attacker is reachability rather than depth: the OMSA host sits on the management network next to BMCs and fabric management interfaces that the attacker's own network position does not reach. Dell does not say which requests can be induced.
Who can reach it
Network access to OMSA with any low-privileged OMSA account.
What to do
Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Restricting egress from OMSA hosts toward management addresses reduces exposure in the interim.
References
Related entries
- AMD processors - frequency scaling / power management: A remote or local attacker times operations and infers secretCVE-2022-23823 · AMD processors - frequency scaling / power managementMedium
- Intel processors - power management throttling: The Intel half of Hertzbleed: observable behaviour in power-managementCVE-2022-24436 · Intel processors - power management throttlingMedium
- Ampere Altra / Altra Max processors: The Arm-server variant of HertzbleedCVE-2022-35888 · Ampere Altra / Altra Max processorsMedium
- AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tagCVE-2023-34471 · AMI MegaRAC SPx (BMC cryptography / HMAC)Medium
- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: Debug code was shipped active in AMD's Video CoreCVE-2024-36319 · AMD Video Decoder Engine Firmware (VCN FW) - debug code left activeMedium
- EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorCVE-2024-38805 · EDK II NetworkPkg (IScsiDxe, iSCSI login response processing)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.