cbcvebase.

Dell Openmanage Enterprise vulnerabilities

24 known vulnerabilities affecting dell/openmanage_enterprise.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM9

Vulnerabilities

Page 1 of 2
CVE-2026-54795P2HIGHCVSS 8.8fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-54795 [HIGH] CWE-78 CVE-2026-54795: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
nvd
CVE-2021-21564P2CRITICALCVSS 9.8fixed in 3.6.12021-08-09
CVE-2021-21564 [CRITICAL] CWE-200 CVE-2021-21564: Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to hijack an elevated session or perform unauthorized actions by sending malformed data.
nvd
CVE-2026-71176P2HIGHCVSS 8.8fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-71176 [HIGH] CWE-89 CVE-2026-71176: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd
CVE-2026-56088P2HIGHCVSS 8.8fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-56088 [HIGH] CWE-89 CVE-2026-56088: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2026-70422P2HIGHCVSS 8.8fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-70422 [HIGH] CWE-89 CVE-2026-70422: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2024-45766P3HIGHCVSS 8.8fixed in 4.2.02024-10-17
CVE-2024-45766 [HIGH] CWE-94 CVE-2024-45766: Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generati Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2026-54796P3HIGHCVSS 7.2fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-54796 [HIGH] CWE-78 CVE-2026-54796: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
nvd
CVE-2022-26857P3HIGHCVSS 8.8fixed in 3.8.4≥ unspecified, < 3.8.42022-05-26
CVE-2022-26857 [HIGH] CWE-285 CVE-2022-26857: Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.
nvd
CVE-2024-25944P3HIGHCVSS 7.5fixed in 4.0.12024-03-29
CVE-2024-25944 [HIGH] CWE-23 CVE-2024-25944: Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenti Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application.
nvd
CVE-2021-21596P3HIGHCVSS 8.8≥ 3.4, ≤ 3.6.12021-08-09
CVE-2021-21596 [HIGH] CWE-200 CVE-2021-21596: Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular version Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the immediate subnet may potentially exploit this vulnerability leading to information disclosure and a possible elevation of privileges.
nvd
CVE-2021-21585P3HIGHCVSS 7.2fixed in 3.6.12021-08-09
CVE-2021-21585 [HIGH] CWE-78 CVE-2021-21585: Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this vulnerability to execute arbitrary OS commands.
nvd
CVE-2021-21530P3HIGHCVSS 8.8≥ unspecified, < 1.30.002021-04-30
CVE-2021-21530 [HIGH] CWE-78 CVE-2021-21530: Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulne Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from the restricted environment and gain access to sensitive information in the system, resulting in information disclosure and elevation of
nvd
CVE-2026-70421P3HIGHCVSS 7.2fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-70421 [HIGH] CWE-269 CVE-2026-70421: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2026-54794P3HIGHCVSS 7.2fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-54794 [HIGH] CWE-918 CVE-2026-54794: Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) v Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd
CVE-2026-70424P3MEDIUMCVSS 6.5fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-70424 [MEDIUM] CWE-22 CVE-2026-70424: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname t Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd
CVE-2026-70423P3MEDIUMCVSS 6.5fixed in 4.7.0fixed in 4.7.0 or later2026-08-19
CVE-2026-70423 [MEDIUM] CWE-611 CVE-2026-70423: Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML Externa Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd
CVE-2024-28961P3HIGHCVSS 7.8v4.0v4.0.12024-04-29
CVE-2024-28961 [HIGH] CWE-256 CVE-2024-28961: Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vu Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade
nvd
CVE-2024-45767P3MEDIUMCVSS 6.5fixed in 4.2.02024-10-17
CVE-2024-45767 [MEDIUM] CWE-89 CVE-2024-45767: Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of S Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2024-28978P3MEDIUMCVSS 6.5v3.10v4.02024-05-01
CVE-2024-28978 [MEDIUM] CWE-284 CVE-2024-28978: Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to unauthorized access to resources.
nvd
CVE-2025-38745P3MEDIUMCVSS 6.5v3.10v4.0+3 more2025-08-14
CVE-2025-38745 [MEDIUM] CWE-532 CVE-2025-38745: Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Inf Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backup and Restore. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd
Dell Openmanage Enterprise vulnerabilities | cvebase