PT-2024-9309 · Dell · Dell Openmanage Server Administrator

Published

2024-12-06

·

Updated

2025-02-04

·

CVE-2024-45760

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell OpenManage Server Administrator versions 11.0.1.0 and prior
Description: The issue is related to an improper access control vulnerability in the Dell OpenManage Server Administrator. This vulnerability can be exploited by a remote low-privileged user via the HTTP GET method, potentially leading to unauthorized actions with elevated privileges.
Recommendations: For Dell OpenManage Server Administrator versions 11.0.1.0 and prior, consider disabling the HTTP GET method until a patch is available to prevent potential exploitation. Restrict access to the vulnerable component to minimize the risk of unauthorized privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-10998
CVE-2024-45760

Affected Products

Dell Openmanage Server Administrator