GPU VulnDB

Database/Control plane, storage & DevOps

Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS Accept

CVE-2025-36593Control plane, storage & DevOpscurated

Impact

An attacker on the local network forges a valid RADIUS Accept in response to a failed authentication - so a rejected login becomes an accepted one. This is the Blast-RADIUS protocol weakness landing in Dell's fabric management tool.

Who can reach it

Local network position between OMNI and the RADIUS server.

What to do

Upgrade OMNI to 3.8. Beyond the patch, the structural fix is running RADIUS over an authenticated transport (RADSEC/TLS) or moving fabric admin auth off RADIUS entirely.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.