GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agent

CVSS 8.1CVE-2026-81478Firmware, BMC & network fabriccurated

Impact

OMSA ships a cryptographic key that is the same on every installation, so knowledge of it (from one binary, anywhere) grants unauthenticated access across an entire fleet at once. This is the shape of bug that turns one node's compromise into fleet-wide access, and no per-node credential rotation helps because the key is in the product. Dell does not say what the key protects.

Who can reach it

Network access to the OMSA service. No authentication required once the shipped key is known.

What to do

Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services - rotating local credentials does not address a key baked into the shipped version. Restrict OMSA reachability to the management network until the rollout is complete.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.