« Back to list

Dell

Dell Openmanage Server Administrator: vulnerabilities and CVEs

Dell Openmanage Server Administrator has 33 published vulnerabilities, 23 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs33
Last 12 months23
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-81447Medium (6.8)0.13%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this…
CVE-2026-81446High (7.4)0.37%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,…
CVE-2026-81445High (7.2)0.46%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,…
CVE-2026-80356High (7.3)0.14%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially…
CVE-2026-81453Medium (6.5)0.44%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access…
CVE-2026-81443Medium (6.4)0.23%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,…
CVE-2026-81442High (8.1)0.38%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,…
CVE-2026-80355Medium (5.4)0.21%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,…
CVE-2026-81481High (7.5)0.53%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access…
CVE-2026-81480High (7.2)0.62%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading…
CVE-2026-81479Medium (5.5)0.17%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…
CVE-2026-81478High (8.1)0.38%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this…
CVE-2026-81477High (7.2)0.62%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading…
CVE-2026-81476Critical (9.8)0.95%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with…
CVE-2026-81475Critical (9.8)0.53%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this…
CVE-2026-81441Medium (5.5)0.11%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this…
CVE-2026-81440Critical (9.8)0.21%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,…
CVE-2026-81474High (7.8)0.15%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…
CVE-2026-81439Medium (6.5)0.17%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…
CVE-2026-81438High (7.5)0.15%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this…
CVE-2026-66269High (7.3)0.37%—Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote…
CVE-2026-56794Medium (6.5)0.45%—Aug 7, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…
CVE-2026-56793Critical (9.8)0.53%—Aug 7, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading…
CVE-2024-45761High (8.1)0.36%—Dec 9, 2024
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web…
CVE-2024-45760High (8.8)0.34%—Dec 9, 2024
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method…
CVE-2024-37130High (7.8)0.17%—Jun 11, 2024
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this…
CVE-2022-34396High (7.8)0.19%—Feb 1, 2023
Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the…
CVE-2021-21514Medium (4.9)5.4%—Mar 2, 2021
Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on…
CVE-2021-21513Critical (9.8)5.9%—Mar 2, 2021
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote…
CVE-2016-4004Medium (4.9)8.9%—Apr 12, 2016
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application8
  2. T1210 Exploitation of Remote Services6
  3. T1059 Command and Scripting Interpreter5
  4. T1068 Exploitation for Privilege Escalation3
  5. T1078 Valid Accounts3
  6. T1005 Data from Local System2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Dell