Dell
Dell Openmanage Enterprise: vulnerabilidades y CVE
Dell Openmanage Enterprise tiene 22 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses10
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71176 | Alta (8.8) | 0.44% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could… |
| CVE-2026-54793 | Media (5.4) | 0.23% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could… |
| CVE-2026-70424 | Media (6.5) | 0.45% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could… |
| CVE-2026-70423 | Media (6.5) | 0.38% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this… |
| CVE-2026-70422 | Alta (8.8) | 0.44% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could… |
| CVE-2026-70421 | Alta (7.2) | 0.46% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… |
| CVE-2026-56088 | Alta (8.8) | 0.44% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could… |
| CVE-2026-54796 | Alta (7.2) | 2.0% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access… |
| CVE-2026-54795 | Alta (8.8) | 2.3% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access… |
| CVE-2026-54794 | Alta (7.2) | 0.27% | — | 19 ago 2026 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to… |
| CVE-2025-38745 | Media (6.5) | 0.23% | — | 14 ago 2025 | Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backup and Restore. A low privileged attacker with remote access could… |
| CVE-2024-45767 | Media (6.5) | 0.32% | — | 17 oct 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access… |
| CVE-2024-45766 | Alta (8.8) | 0.58% | — | 17 oct 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit… |
| CVE-2024-28979 | Media (4.8) | 0.26% | — | 1 may 2024 | Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could… |
| CVE-2024-28978 | Media (6.5) | 0.44% | — | 1 may 2024 | Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to unauthorized access to… |
| CVE-2024-28961 | Alta (7.8) | 0.15% | — | 29 abr 2024 | Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials… |
| CVE-2024-25944 | Alta (7.5) | 0.77% | — | 29 mar 2024 | Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on… |
| CVE-2022-26857 | Alta (8.8) | 0.97% | — | 26 may 2022 | Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked… |
| CVE-2021-21596 | Alta (8.8) | 0.75% | — | 9 ago 2021 | Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the… |
| CVE-2021-21585 | Alta (7.2) | 2.1% | — | 9 ago 2021 | Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this… |
| CVE-2021-21584 | Media (6.5) | 0.81% | — | 9 ago 2021 | Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this… |
| CVE-2021-21564 | Crítica (9.8) | 1.6% | — | 9 ago 2021 | Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to hijack an elevated session or perform… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Dell
Secure Connect Gateway · 135Data Domain Operating System · 99Powerscale Onefs · 98EMC Powerscale Onefs · 84Wyse Management Suite · 70Latitude 9410 Firmware · 65Latitude 5411 Firmware · 64Latitude 5511 Firmware · 64Latitude 7410 Firmware · 63Latitude 7310 Firmware · 63Latitude 5310 Firmware · 62Latitude 5400 Firmware · 62