Database/Firmware, BMC & network fabric
Dell OMSA: unauthenticated OS command injection gives remote execution on the managed node
Impact
OMSA passes externally supplied input into an OS command without neutralising special elements, so an unauthenticated network attacker can run commands in the context of the OMSA agent. That agent is privileged and sits on the host that runs the accelerators, so a compromise is host compromise on a GPU node plus control of that node's hardware management surface. Dell does not state which handler is affected.
Who can reach it
Network access to the OMSA service on a managed node. No authentication required.
What to do
Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Where the upgrade cannot be scheduled immediately, keep the OMSA port firewalled to the management VLAN or uninstall the agent. No vendor workaround is published.
References
Related entries
- Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agentCVE-2026-81478 · Dell OpenManage Server Administrator (hard-coded cryptographic key)High
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-004-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-010-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integratedCVE-2021-21505 · Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account)High
- Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes controlCVE-2024-25951 · Dell iDRAC8 (local RACADM)High
- Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by gettingCVE-2024-37774 · Sunbird DCIM dcTrack v9.1.2High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.