First published: Tue Mar 02 2021(Updated: )
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain admin access on the affected system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell OpenManage Server Administrator | <9.4.0.3 | |
Dell OpenManage Server Administrator | >=9.5.0.0<9.5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21513 is classified as a high severity vulnerability due to its potential for enabling remote unauthenticated access to admin functionalities.
To mitigate CVE-2021-21513, upgrade to Dell EMC OpenManage Server Administrator version 9.5.0.1 or later, or apply the recommended patches.
CVE-2021-21513 affects Dell EMC OpenManage Server Administrator installations version 9.4 and below, with Distributed Web Server enabled.
An authentication bypass vulnerability like CVE-2021-21513 allows attackers to access system features without proper authentication, potentially compromising administrative control.
Yes, CVE-2021-21513 can be exploited remotely by an attacker due to the nature of the authentication bypass.