Executive brief
Dell OpenManage Server Administrator is an administrative tool used to manage Dell servers and their hardware. This vulnerability in certificate validation allows an attacker on the same network to intercept and tamper with communications to the system, potentially exposing sensitive server management data or modifying system configurations without authorization.
Technical details
The vulnerability is an improper certificate validation flaw in Dell OpenManage Server Administrator versions prior to 11.1.0.3. An unauthenticated attacker with adjacent network access can exploit this weakness to bypass certificate verification controls. This enables man-in-the-middle (MITM) attacks on the administrative interface, allowing an attacker to eavesdrop on or modify management communications. The attack requires no user interaction and can lead to both information disclosure (capturing sensitive data transmitted during management operations) and information tampering (modifying system state through the compromised channel). Patches are available in version 11.1.0.3 and later.
Affected products
- Dell OpenManage Server Administrator prior to 11.1.0.3
Timeline
- 2026-09-17: disclosed