Database/Firmware, BMC & network fabric
Dell OMSA: authenticated path traversal lets a low-privileged user read files off the node
Impact
A holder of a low-privileged OMSA account can read files outside the intended directory on the managed node. That turns a monitoring-level account - the kind handed to NOC staff or to an integration - into arbitrary file read on a GPU host, where node credentials and cluster tokens live. Dell does not name the affected handler or the reachable paths.
Who can reach it
Network access to OMSA with any low-privileged OMSA account.
What to do
Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Review which accounts and integrations hold low-privileged OMSA access in the meantime.
References
Related entries
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: RNICs cacheNCVD-2019-003-rnic-on-board-sram-metadata-cach · RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NICMedium
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: RNICs cacheNCVD-2019-006-rnic-on-board-sram-metadata-cach · RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NICMedium
- RoCEv2 congestion control - DCQCN, ECN marking and Congestion Notification Packets: DCQCN reacts to ECN marks by havingNCVD-2022-003-rocev2-congestion-control-dcqcn · RoCEv2 congestion control - DCQCN, ECN marking and Congestion Notification PacketsMedium
- RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMA: This is the paper thatNCVD-2023-006-rnic-microarchitectural-resource · RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMAMedium
- RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMA: This is the paper thatNCVD-2023-008-rnic-microarchitectural-resource · RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMAMedium
- TPM 2.0 (S3 sleep PCR reset): Platform Configuration Registers can be reset without a full platform restart by abusingCVE-2018-6622 · TPM 2.0 (S3 sleep PCR reset)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.