Sceawere

Vulnerability Detail

CVE-2026-70424UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dell OpenManage Enterprise Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Dell
Product
OpenManage Enterprise
Attack Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-19T14:17:39.190Z",
  "pubdate": "2026-08-19T14:17:39.190Z",
  "executiveSummary": "Dell OpenManage Enterprise in versions prior to 4.7.0 suffers from an Improper Limitation of a Pathname to a Restricted Directory vulnerability, commonly categorized as path traversal. This security flaw enables a remote attacker possessing low-privileged access to interact with the application and potentially achieve unauthorized information exposure. The presence of this vulnerability poses significant risk to enterprise infrastructure management environments, as sensitive system files or internal data structures may be accessed without proper authorization. Exploitation requires remote network access and low-level user privileges within the targeted Dell OpenManage Enterprise ecosystem. Organizations deploying vulnerable instances face potential confidentiality breaches, exposing critical operational data to malicious actors. Immediate remediation through vendor-supplied software updates is strongly advised to eliminate the path traversal vector and secure the administrative platform against unauthorized data retrieval attempts.",
  "technicalDetails": "The vulnerability resides within the file handling and directory management components of Dell OpenManage Enterprise in versions prior to 4.7.0. The root cause stems from insufficient input validation and improper sanitization of user-supplied path parameters, allowing traversal sequences such as dot-dot-slash patterns to bypass intended structural boundaries. Because the application fails to adequately restrict file system navigation to authorized directories, a remote threat actor can supply specially crafted inputs that traverse outside the restricted root directory.\nThe attack vector involves network-based interactions where a low-privileged authenticated user submits malicious path traversal sequences via vulnerable endpoints exposed by the management service. Upon receiving the input, the underlying component fails to canonicalize or restrict the path effectively, causing the application to process the request against unauthorized file system locations. This behavior leads directly to information exposure, permitting the retrieval of sensitive files accessible to the security context of the web application process.\nPrerequisites for successful exploitation include network reachability to the Dell OpenManage Enterprise administrative interface and valid low-privileged credentials to interact with the vulnerable functionalities. The payload behavior centers on directory traversal strings designed to breach file system jails, resulting in the unauthorized disclosure of internal system configurations, logs, or other sensitive operational data stored within the server architecture. Post-exploitation impact is primarily characterized by severe information disclosure, which may facilitate subsequent attacks against the broader enterprise infrastructure managed by the affected platform."
}
CVE-2026-70424: Dell OpenManage Enterprise Path Traversal Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere