CVE-2024-45760

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*

History

04 Feb 2025, 18:04

Type Values Removed Values Added
First Time Dell openmanage Server Administrator
Dell
References () https://www.dell.com/support/kbdoc/en-us/000258320/dsa-2024-481-security-update-for-dell-openmanage-server-administrator-omsa-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000258320/dsa-2024-481-security-update-for-dell-openmanage-server-administrator-omsa-vulnerability - Mitigation, Vendor Advisory
CPE cpe:2.3:a:dell:openmanage_server_administrator:*:*:*:*:*:*:*:*
Summary
  • (es) Dell OpenManage Server Administrator, versiones 11.0.1.0 y anteriores, contiene una vulnerabilidad de control de acceso inadecuado. Un usuario remoto con pocos privilegios podría aprovechar esta vulnerabilidad a través del método HTTP GET, lo que daría lugar a una acción no autorizada con privilegios elevados.

09 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 17:15

Updated : 2025-02-04 18:04


NVD link : CVE-2024-45760

Mitre link : CVE-2024-45760

CVE.ORG link : CVE-2024-45760


JSON object : View

Products Affected

dell

  • openmanage_server_administrator
CWE
CWE-862

Missing Authorization