Database/Control plane, storage & DevOps
Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executes
CVE-2024-45766Control plane, storage & DevOpscurated
Impact
A low-privileged remote user injects code into OME and executes it. OME manages iDRACs fleet-wide, so code execution there means credentialed access to every BMC it manages.
Who can reach it
Authenticated low-privilege user of the OME web console, with interaction.
What to do
Upgrade OME past 4.1. Application upgrade with a service restart. Treat OME as tier-0: it holds fleet-wide BMC credentials, so compromise there is equivalent to compromising every server it manages.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.