CVE-2016-4004 describes a directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) version 8.2. This flaw allows remote, authenticated administrators to read arbitrary files on the system by manipulating the 'file' parameter with a '..\ (dot dot backslash)' sequence when calling the 'ViewFile' function. The vulnerability carries a CVSS score of 4.9 (Medium) and is rated as high risk by FAUCET (86/100). It requires high privileges (PR:H) for exploitation, but once authenticated, an attacker can achieve high confidentiality impact (C:H) without user interaction. While not listed on the CISA KEV catalog or showing active exploitation, an exploit module for this vulnerability (EDB-39486) is publicly available on ExploitDB. Despite this, there is no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.2CPE matchmatch criteria | cpe:2.3:a:dell:openmanage_server_administrator:8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.