Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

DSA-2020-023: Dell EMC OpenManage Enterprise & Enterprise-Modular Multiple Vulnerabilities

Summary: Dell EMC OpenManage Enterprise and Enterprise-Modular has been updated to address multiple vulnerabilities which may be potentially exploited to compromise the system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Critical

Details

  • SQL Injection Vulnerability (CVE-2020-5320)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions.

CVSSv3 Base Score 9.0 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H)
  • Improper Input Validation Vulnerability (CVE-2020-5321)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to spawn tasks with elevated privileges.
           
CVSSv3 Base Score 7.6 (AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H)
  • Command Injection Vulnerability (CVE-2020-5322)
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00  contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system.
           
CVSSv3 Base Score 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
 
  • Injection Vulnerability (CVE-2020-5323)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00  contain an injection vulnerability.  A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain access to sensitive information or cause denial-of-service.
           
CVSSv3 Base Score 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L)
  • SQL Injection Vulnerability (CVE-2020-5320)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions.

CVSSv3 Base Score 9.0 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H)
  • Improper Input Validation Vulnerability (CVE-2020-5321)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to spawn tasks with elevated privileges.
           
CVSSv3 Base Score 7.6 (AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H)
  • Command Injection Vulnerability (CVE-2020-5322)
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00  contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system.
           
CVSSv3 Base Score 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
 
  • Injection Vulnerability (CVE-2020-5323)
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00  contain an injection vulnerability.  A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain access to sensitive information or cause denial-of-service.
           
CVSSv3 Base Score 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L)
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation




Affected products:
 
  • Dell EMC OpenManage Enterprise (OME) versions prior to 3.2
  • Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00  

Remediation:      
The following Dell EMC OpenManage Enterprise (OME) and OpenManage Enterprise-Modular (OME-M) releases contain resolutions to these vulnerabilities:
  • Dell EMC OpenManage Enterprise (OME) 3.2 and later
  • Dell EMC OpenManage Enterprise-Modular (OME-M) 1.10.00 and later
Dell EMC recommends all customers upgrade at the earliest opportunity.  

Customers can download for PowerEdge servers. For all other platforms, please select the platform from the Dell support site.



Affected products:
 
  • Dell EMC OpenManage Enterprise (OME) versions prior to 3.2
  • Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00  

Remediation:      
The following Dell EMC OpenManage Enterprise (OME) and OpenManage Enterprise-Modular (OME-M) releases contain resolutions to these vulnerabilities:
  • Dell EMC OpenManage Enterprise (OME) 3.2 and later
  • Dell EMC OpenManage Enterprise-Modular (OME-M) 1.10.00 and later
Dell EMC recommends all customers upgrade at the earliest opportunity.  

Customers can download for PowerEdge servers. For all other platforms, please select the platform from the Dell support site.

Related Information

Affected Products

Dell EMC OpenManage Enterprise
Article Properties
Article Number: 000176929
Article Type: Dell Security Advisory
Last Modified: 21 Feb 2021
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.