DSA-2021-060: Dell OpenManage Enterprise-Modular (OME-M) Security Update for a Bypass Vulnerability
Summary: Dell OpenManage Enterprise-Modular (OME-M) remediation is available for a security bypass vulnerability that may be exploited to compromise the affected systems.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Details
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21530 | Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from the restricted environment and gain access to sensitive information in the system, resulting in information disclosure and elevation of privilege. | 8.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21530 | Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from the restricted environment and gain access to sensitive information in the system, resulting in information disclosure and elevation of privilege. | 8.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H |
Affected Products & Remediation
| Product | Affected Version(s) | Updated Version(s) | Link to Update |
| OpenManage Enterprise-Modular (OME-M) | Versions prior to 1.30.00 | 1.30.00 | OpenManage Enterprise Modular v1.30.00 | Driver Details | Dell US |
| Product | Affected Version(s) | Updated Version(s) | Link to Update |
| OpenManage Enterprise-Modular (OME-M) | Versions prior to 1.30.00 | 1.30.00 | OpenManage Enterprise Modular v1.30.00 | Driver Details | Dell US |
Revision History
| Revision | Date | Description |
| 1.0 | 2020-04-12 | Initial Release |
Acknowledgements
CVE-2021-21530: Dell would like to thank Thorsten Tüllmann of Karlsruhe Institute of Technology
Related Information
Legal Disclaimer
Affected Products
Dell OpenManage Enterprise-ModularProducts
Product Security InformationArticle Properties
Article Number: 000185205
Article Type: Dell Security Advisory
Last Modified: 13 Apr 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.