DSA-2026-358: Security Update for Dell OpenManage Python SDK (omsdk) Vulnerability

Zusammenfassung: Dell Open Manage Python SDK (omsdk) remediation is available for a security vulnerability that could be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-68864  Dell Open Manage Python SDK (omsdk) contains an improper TLS certificate validation issue in the redfish_operation execution path. The SDK exposes a verify_ssl configuration option intended to control certificate validation. However, WsManProtocolBase.redfish_operation ignores this setting and unconditionally disables certificate validation by passing verify=False to the underlying HTTP request. As a result, an operator explicitly enabling TLS verification with verify_ssl=True still performs Redfish communication without certificate validation. 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-68864  Dell Open Manage Python SDK (omsdk) contains an improper TLS certificate validation issue in the redfish_operation execution path. The SDK exposes a verify_ssl configuration option intended to control certificate validation. However, WsManProtocolBase.redfish_operation ignores this setting and unconditionally disables certificate validation by passing verify=False to the underlying HTTP request. As a result, an operator explicitly enabling TLS verification with verify_ssl=True still performs Redfish communication without certificate validation. 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

Product Affected Versions Remediated Versions Link
Dell Open Manage Python SDK (omsdk)  Versions prior to 1.2.519 
Version 1.2.519 or later
Support Page
Product Affected Versions Remediated Versions Link
Dell Open Manage Python SDK (omsdk)  Versions prior to 1.2.519 
Version 1.2.519 or later
Support Page

Workarounds und Korrekturmaßnahmen

None

Revisionsverlauf

"

RevisionDateDescription
1.02026-09-02Initial Release

Danksagung

Dell would like to thank Rudra_16 for reporting this issue.

Zugehörige Informationen

Betroffene Produkte

OpenManage Ansible Modules
Artikeleigenschaften
Artikelnummer: 000505139
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 02 Sept. 2026
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.