GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: authenticated SSRF lets a low-privileged user reach systems behind the agent

CVSS 6.4CVE-2026-81443Firmware, BMC & network fabriccurated

Impact

A low-privileged OMSA account can make the agent issue requests to systems it chooses, with a scope change and low confidentiality and integrity impact. The value to an attacker is reachability rather than depth: the OMSA host sits on the management network next to BMCs and fabric management interfaces that the attacker's own network position does not reach. Dell does not say which requests can be induced.

Who can reach it

Network access to OMSA with any low-privileged OMSA account.

What to do

Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Restricting egress from OMSA hosts toward management addresses reduces exposure in the interim.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.