CVE-2019-3723

CRITICAL

Dell EMC OpenManage Server Administrator < 9.1.0.3 & < 9.2.0.4 - Unauthenticated Arbitrary File Write & Deletion

Title source: llm
STIX 2.1

Description

Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation

References (2)

Core 2

Scores

CVSS v3 9.1
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-20
Status published
Products (6)
dell/emc_openmanage_server_administrator 9.1
dell/emc_openmanage_server_administrator 9.1.0.1
dell/emc_openmanage_server_administrator 9.1.0.2
dell/emc_openmanage_server_administrator 9.2
dell/emc_openmanage_server_administrator 9.2.0.1
dell/emc_openmanage_server_administrator 9.2.0.2
Published Jun 06, 2019
Tracked Since Feb 18, 2026