Database/Firmware, BMC & network fabric
Dell OMSA: unauthenticated path traversal exposes arbitrary files from the managed node
Impact
An unauthenticated network attacker can read files outside the intended directory through the OMSA service. On a GPU host that filesystem holds kubelet and container runtime configuration, service-account tokens, driver and fabric configuration, and often credentials for the scheduler or storage - so file read on one node is a credential-harvesting step into the wider cluster. Dell does not state which paths are reachable. CVE-2026-81453 is a separate traversal that requires a low-privileged account.
Who can reach it
Network access to the OMSA service on a managed node. No authentication required.
What to do
Upgrade OMSA to 11.1.0.3 or later on every managed node and restart the OMSA services. Keep the OMSA port off any tenant-reachable network until patched, and treat credentials stored on exposed nodes as candidates for rotation.
References
Related entries
- FreeIPMI ipmi-oem: stack buffer over-read when a BMC returns a short Fujitsu SEL responseCVE-2026-85505 · FreeIPMI ipmi-oem (Fujitsu get-sel-entry-long-text handler)High
- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: RoCE requires a lossless network, which inNCVD-2018-001-rocev2-lossless-ethernet-fabric · RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow ControlHigh
- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: RoCE requires a lossless network, which inNCVD-2018-006-rocev2-lossless-ethernet-fabric · RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow ControlHigh
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: RNICs hold per-connection state in aNCVD-2021-005-infiniband-roce-communication-ma · InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resourcesHigh
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: RNICs hold per-connection state in aNCVD-2021-011-infiniband-roce-communication-ma · InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resourcesHigh
- OpenBMC bmcweb HTTP/1.1 Expect: 100-continue handling: bmcweb applies a 4 KB body limit to unauthenticated requestsNCVD-2026-001-openbmc-bmcweb-http-1-1-expect-1 · OpenBMC bmcweb HTTP/1.1 Expect: 100-continue handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.