Impact
Dell RecoverPoint for Virtual Machines contains an OS Command Injection vulnerability caused by improper neutralization of special elements used in an OS command. A high privileged attacker with remote access could exploit this flaw to execute arbitrary operating system commands on the appliance. The resulting compromise would give the attacker full control over the device, potentially allowing data tampering, service disruption, or further lateral movement within the environment.
Affected Systems
The vulnerability affects Dell RecoverPoint for Virtual Machines versions 6.0.3 and 6.0.3.1. Systems running either of these releases are susceptible to the command injection flaw.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires remote access with high privileges, which increases risk for organizations exposing the RecoverPoint management interface to untrusted networks. The CVSS score of 7.2 indicates a high severity, but the vulnerability is not listed in the CISA KEV catalog and the EPSS score indicates a 1% probability of exploitation. The attacker, upon successful exploitation, can gain complete control over the appliance, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment