Executive brief
Dell Server Hardware Manager is a tool used to monitor and manage server hardware components. A security flaw in this software allows a user with low-level access to the server to gain higher-level administrative privileges. This could allow an unauthorized person to take full control of the server, potentially leading to data theft or service disruption.
Technical details
An improper access control vulnerability (CWE-284) exists in Dell Server Hardware Manager versions prior to 3.2.2. The flaw allows a local, authenticated attacker with low privileges to bypass intended access restrictions. By exploiting this vulnerability, an attacker can achieve an elevation of privileges to a higher level, such as administrator or SYSTEM. The attack requires local access to the host operating system but no user interaction. Dell has released version 3.2.2 to remediate this issue.
Affected products
- Dell Server Hardware Manager prior to 3.2.2
Timeline
- 2026-06-17: advisory: Initial release of Dell Security Advisory DSA-2026-243
- 2026-06-19: disclosed: NVD publication date