Insecure MySQL Configuration Vulnerability
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 9.1%
from disclosure to weapon0 days
Published on NVDNov 30
1st PoCNov 14
exploitation probability
9.1%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short
Dell OpenManage Network Manager versions before 6.5.0 had an insecure MySQL setup that allowed database users to read and write files on the server. This could let attackers access sensitive data or modify system files.
Technical detail
The vulnerability stems from insecure default MySQL configuration in embedded database instances, granting FILE privilege to database users without restriction. An attacker with database access can leverage INTO OUTFILE/LOAD_FILE functionality to exfiltrate sensitive files or inject malicious content into the filesystem, potentially leading to privilege escalation or code execution depending on file permissions.
Summary generated and translated by AI from the official description.
Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database.
Affected products
Dell · OpenManage Network Managerpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45852cve_referencewww.exploit-db.com/exploits/45852/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.