Executive brief
Dell OpenManage Server Administrator is a management tool used to monitor and control enterprise servers. This vulnerability allows an unauthenticated remote attacker to access sensitive information through the use of weak cryptographic algorithms, potentially exposing server management credentials or configuration data.
Technical details
Dell OpenManage Server Administrator versions prior to 11.1.0.3 use a broken or risky cryptographic algorithm for protecting sensitive data. The vulnerability is classified as CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) and can be exploited by an unauthenticated attacker with remote network access. The attack has high complexity (AC:H) but requires no user interaction. Successful exploitation leads to information disclosure. The fix is available in version 11.1.0.3 and later.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fixed in version 11.1.0.3