DSA-2024-426: Security Update for Dell OpenManage Enterprise Vulnerabilities
Summary: Dell OpenManage Enterprise remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2024-45766 |
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
8.0 |
|
| CVE-2024-45767 |
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
4.3 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2024-45766 |
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
8.0 |
|
| CVE-2024-45767 |
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
4.3 |
Affected Products & Remediation
| Product |
Affected Versions |
Remediated Versions |
Link |
| Dell OpenManage Enterprise |
Versions prior to 4.2.0 |
4.2.0 |
| Product |
Affected Versions |
Remediated Versions |
Link |
| Dell OpenManage Enterprise |
Versions prior to 4.2.0 |
4.2.0 |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-10-16 |
Initial Release |
Acknowledgements
Dell would like to thank B4gpipe for reporting these issues.