Junglewise Threat Intelligence

CVE-2024-24909: Dell OpenManage Integration with Windows Admin Center RCE in gateway plugin

CVE-2024-24909 · Severity: high · CVSS 8.8 · Published 2026-06-16

Vendors: Dell.

Executive brief

Dell OpenManage Integration with Microsoft Windows Admin Center, a tool used by IT administrators to manage Dell servers through a centralized console, contains a security flaw in its gateway plugin. An attacker with basic user credentials could exploit this vulnerability to take full control of the management system and run unauthorized commands. This could lead to a total compromise of the server management infrastructure and unauthorized access to sensitive hardware configurations.

Technical details

A remote code execution (RCE) vulnerability exists in the gateway plugin of Dell OpenManage Integration with Microsoft Windows Admin Center (OMIMSWAC). The flaw is classified as a command injection vulnerability (CWE-77) resulting from improper neutralization of special elements used in a command. An authenticated attacker with low privileges can exploit this over the network without user interaction to escalate their privileges and execute arbitrary code. Dell has released version 3.2 to address this issue; there are no known workarounds.

Affected products

  • Dell OpenManage Integration with Microsoft Windows Admin Center Prior to and including 3.1

Timeline

  • 2024-02-14: advisory: Initial Dell security advisory (DSA-2024-084) published
  • 2024-02-14: patched: Remediated in version 3.2
  • 2026-06-16: disclosed: NVD publication date

References