securityonline.info 1 Oct 2026, 02:31 UTC

Dell Warns Terraform Users of TLS Flaw Enabling Management Traffic Interception

Dell Warns Terraform Users of TLS Flaw Enabling Management Traffic Interception

DELL has published an advisory detailing four vulnerabilities in the Dell Terraform Provider family, affecting plugins used to automate Dell server management via Terraform. The flaws span the Redfish provider and the OpenManage Enterprise (OME) provider, with one particularly severe issue that disables TLS certificate validation in the base HTTP transport.

Dell notes that the most critical flaw could enable man-in-the-middle interception of management traffic, though there is currently no evidence of active exploitation in the wild. The advisory also indicates that there has been no public PoC exploit published to date.

The vulnerabilities are tied to four CVEs: CVE-2026-91881 (TLS verification disabled in the Redfish provider’s transport layer), CVE-2026-91882 (exposure of sensitive data during API error handling via externally accessible files), CVE-2026-76113 (exposure of sensitive data via the redfish_certificate resource), and CVE-2026-91883 (plaintext logging of secure configuration data). Affected versions are the Redfish provider prior to 1.6.2 and the OME provider from 1.0.0 through 1.2.3.

Dell has released patched versions—Redfish provider 1.6.2 and OME provider 1.2.4—and urges administrators to upgrade to restore certificate validation and mitigate credential exposure. The article notes that while there is no confirmed exploitation, unpatched systems remain highly susceptible to credential theft and unauthorised access, making timely remediation essential.

View full article

Article by CyberSIXT