DSA-2026-358: Security Update for Dell OpenManage Python SDK (omsdk) Vulnerability

Riepilogo: Dell Open Manage Python SDK (omsdk) remediation is available for a security vulnerability that could be exploited by malicious users to compromise the affected system.

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

High

Dettagli

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-68864  Dell Open Manage Python SDK (omsdk) contains an improper TLS certificate validation issue in the redfish_operation execution path. The SDK exposes a verify_ssl configuration option intended to control certificate validation. However, WsManProtocolBase.redfish_operation ignores this setting and unconditionally disables certificate validation by passing verify=False to the underlying HTTP request. As a result, an operator explicitly enabling TLS verification with verify_ssl=True still performs Redfish communication without certificate validation. 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-68864  Dell Open Manage Python SDK (omsdk) contains an improper TLS certificate validation issue in the redfish_operation execution path. The SDK exposes a verify_ssl configuration option intended to control certificate validation. However, WsManProtocolBase.redfish_operation ignores this setting and unconditionally disables certificate validation by passing verify=False to the underlying HTTP request. As a result, an operator explicitly enabling TLS verification with verify_ssl=True still performs Redfish communication without certificate validation. 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Product Affected Versions Remediated Versions Link
Dell Open Manage Python SDK (omsdk)  Versions prior to 1.2.519 
Version 1.2.519 or later
Support Page
Product Affected Versions Remediated Versions Link
Dell Open Manage Python SDK (omsdk)  Versions prior to 1.2.519 
Version 1.2.519 or later
Support Page

Soluzioni alternative e mitigazioni

None

Cronologia delle revisioni

"

RevisionDateDescription
1.02026-09-02Initial Release

Ringraziamenti

Dell would like to thank Rudra_16 for reporting this issue.

Informazioni correlate

Prodotti interessati

OpenManage Ansible Modules
Proprietà dell'articolo
Numero articolo: 000505139
Tipo di articolo: Dell Security Advisory
Ultima modifica: 02 set 2026
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.