CVE-2019-3721: Improper Range Header Processing Vulnerability
Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to cause the application to compress each of the requested bytes, resulting in a crash due to excessive memory consumption and preventing users from accessing the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3721?
CVE-2019-3721 is a vulnerability in Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 that allows a remote unauthenticated attacker to cause the application to compress each requested byte.
What is the severity of CVE-2019-3721?
The severity of CVE-2019-3721 is high with a CVSS score of 7.5.
How does CVE-2019-3721 affect Dell EMC Open Manage System Administrator (OMSA)?
CVE-2019-3721 affects Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0.
How can an attacker exploit CVE-2019-3721?
An attacker can exploit CVE-2019-3721 by sending crafted requests with overlapping ranges to the vulnerable application.
Is there a fix for CVE-2019-3721?
Yes, upgrading Dell EMC Open Manage System Administrator (OMSA) to version 9.3.0 or later will fix the CVE-2019-3721 vulnerability.