Database/Firmware, BMC & network fabric
Dell OMSA: remote heap overflow gives code execution to a high-privileged account
Impact
A remote attacker holding a high-privileged OMSA account can overflow a heap buffer and execute code in the agent's context on the managed node. Because it needs administrative OMSA credentials it is mainly a path from management-plane credential theft to host code execution on the GPU node - a stolen or reused OMSA admin password becomes root-equivalent on every node it works on. Distinct from CVE-2026-81474 (local, low-privileged) and CVE-2026-81480 (stack overflow).
Who can reach it
Network access to OMSA with a high-privileged (administrative) OMSA account.
What to do
Upgrade OMSA to 11.1.0.3 or later on all managed nodes and restart the OMSA services. Rotating shared OMSA administrative credentials is worth doing alongside the patch.
References
Related entries
- Dell OMSA: remote stack overflow gives code execution to a high-privileged accountCVE-2026-81480 · Dell OpenManage Server Administrator (stack-based buffer overflow)High
- Intel CSME / Converged Security and Management Engine (mask ROM): A flaw in the CSME boot ROM window before memoryCVE-2019-0090 · Intel CSME / Converged Security and Management Engine (mask ROM)High
- Dell iDRAC9 (web interface, local file inclusion): A path-traversal / local-file-inclusion flaw lets a low-privilegeCVE-2020-5366 · Dell iDRAC9 (web interface, local file inclusion)High
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCCVE-2021-21539 · Dell iDRAC9High
- AMD SEV-ES firmware - TMR placement in MMIO space: SEV-ES firmware does not verify that the Trusted Memory Region isCVE-2021-26332 · AMD SEV-ES firmware - TMR placement in MMIO spaceHigh
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: Insufficient bounds checking while the ASPCVE-2021-26402 · AMD Secure Processor firmware - BIOS mailbox command bounds checkingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.