PT-2019-16666 · Dell Emc · Dell Emc Openmanage System Administrator

Published

2019-04-25

·

Updated

2023-02-03

·

CVE-2019-3721

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0
Description The issue is related to improper range header processing. A remote unauthenticated attacker can send crafted requests with overlapping ranges, causing the application to compress each of the requested bytes. This results in a crash due to excessive memory consumption, preventing users from accessing the system.
Recommendations For versions prior to 9.3.0, update to version 9.3.0 or later to resolve the issue.

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2019-3721

Affected Products

Dell Emc Openmanage System Administrator