Information Disclosure in Dell OpenManage Enterprise by Dell
CVE-2021-21584

7.7HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
9 August 2021

Summary

Dell OpenManage Enterprise versions 3.5 and OpenManage Enterprise-Modular version 1.30.00 are susceptible to an information disclosure vulnerability. This issue could allow an authenticated attacker with low privileges to exploit the system, leading to the unauthorized disclosure of sensitive OIDC server credentials. As a result, an attacker could gain access to critical information that may compromise the integrity and security of the affected servers.

Affected Version(s)

Dell OpenManage Enterprise < 3.6.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.