Impact
Dell RecoverPoint for Virtual Machines contains an OS Command Injection vulnerability caused by improper neutralization of special elements used in an OS command. A high privileged attacker with remote access could exploit this flaw to execute arbitrary operating system commands on the appliance. The resulting compromise would give the attacker full control over the device, potentially allowing data tampering, service disruption, or further lateral movement within the environment.
Affected Systems
The vulnerability affects Dell RecoverPoint for Virtual Machines versions 6.0.3 and 6.0.3.1. Systems running either of these releases are susceptible to the command injection flaw.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, but the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and the EPSS score is not available. Exploitation requires remote access with high privileges, suggesting a moderate to high risk for organizations that expose the RecoverPoint management interface to untrusted networks. An attacker who successfully exploits the flaw can gain complete control over the appliance, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment