Impact
The vulnerability is an Improper Authentication flaw in Dell ObjectScale running versions earlier than 4.4.0.0. It permits an unauthenticated attacker with remote access to bypass the system’s authentication controls and gain unauthorized access, potentially exposing data and configuration settings.
Affected Systems
All installations of Dell ObjectScale prior to version 4.4.0.0 are affected. The flaw applies to the overall product as no subcomponent is singled out, so any older release could be vulnerable if exposed to remote exposure.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and unauthenticated, meaning an attacker could exploit the flaw from outside the network if the system is reachable. Because the impact is high while the exploitation probability is relatively low, the recommended response is to patch promptly while maintaining vigilance for any incidents.
OpenCVE Enrichment