Impact
The vulnerability is an improper verification of the source of a communication channel in the REST API of Dell PowerProtect Data Manager, allowing a high‑privileged attacker with remote access to create an unverified channel that the service accepts, thereby bypassing the protection mechanism that safeguards the data manager.
Affected Systems
Dell PowerProtect Data Manager versions prior to 19.22, exposed through its network‑facing REST API.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The EPSS score is less than 1%, showing a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the REST API, and an attacker would need high‑privileged credentials to exploit the flaw.
OpenCVE Enrichment