Database/Control plane, storage & DevOps
Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS Accept
CVE-2025-36593Control plane, storage & DevOpscurated
Impact
An attacker on the local network forges a valid RADIUS Accept in response to a failed authentication - so a rejected login becomes an accepted one. This is the Blast-RADIUS protocol weakness landing in Dell's fabric management tool.
Who can reach it
Local network position between OMNI and the RADIUS server.
What to do
Upgrade OMNI to 3.8. Beyond the patch, the structural fix is running RADIUS over an authenticated transport (RADSEC/TLS) or moving fabric admin auth off RADIUS entirely.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.