Database/Firmware, BMC & network fabric
Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agent
Impact
OMSA ships a cryptographic key that is the same on every installation, so knowledge of it (from one binary, anywhere) grants unauthenticated access across an entire fleet at once. This is the shape of bug that turns one node's compromise into fleet-wide access, and no per-node credential rotation helps because the key is in the product. Dell does not say what the key protects.
Who can reach it
Network access to the OMSA service. No authentication required once the shipped key is known.
What to do
Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services - rotating local credentials does not address a key baked into the shipped version. Restrict OMSA reachability to the management network until the rollout is complete.
References
Related entries
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-004-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-010-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integratedCVE-2021-21505 · Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account)High
- Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes controlCVE-2024-25951 · Dell iDRAC8 (local RACADM)High
- Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by gettingCVE-2024-37774 · Sunbird DCIM dcTrack v9.1.2High
- NVIDIA UFM Enterprise: code injection via the plugin management API from a low-privileged accountCVE-2026-24169 · NVIDIA UFM Enterprise (plugin management API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.