Database/Firmware, BMC & network fabric
Dell OMSA: partial string comparison flaw lets a low-privileged local user cause a denial of service
Impact
A separate defect in the same OMSA release train: a partial string comparison that a low-privileged local account can abuse to make the hardware management agent unavailable. Reported as availability-only, with no disclosure, no tampering and no privilege gain. The operator consequence on a GPU host is the same as the companion issue - loss of in-band chassis, PSU, thermal and RAID telemetry for that node - but the mechanism and the preconditions differ, so it is tracked on its own.
Who can reach it
Local, authenticated as any low-privileged user on the node running the OMSA managed-node service. No network reachability required (AV:L, PR:L).
What to do
Upgrade the OMSA managed-node package to 11.1.0.3 or later per Dell DSA-2026-403 - the same release that addresses the companion OMSA issue, so patch both in one pass. Package update plus an OMSA service restart; the advisory does not call for a firmware flash or a host reboot.
References
Related entries
- Dell OMSA: missing authentication on a critical function lets a local user crash the management agentCVE-2026-81441 · Dell OpenManage Server Administrator (OMSA) managed-node agentMedium
- Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial portCVE-2019-14456 · Opengear console server (serial port logging)Medium
- AMD Secure Processor bootloader - SPIROM upgrade path: An attacker who can drive the SPIROM upgrade path can passCVE-2025-48515 · AMD Secure Processor bootloader - SPIROM upgrade pathMedium
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSCVE-2025-7623 · Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-FMedium
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.