Description
Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-08-19
Score: 7.2 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell RecoverPoint for Virtual Machines contains an OS Command Injection vulnerability caused by improper neutralization of special elements used in an OS command. A high privileged attacker with remote access could exploit this flaw to execute arbitrary operating system commands on the appliance. The resulting compromise would give the attacker full control over the device, potentially allowing data tampering, service disruption, or further lateral movement within the environment.

Affected Systems

The vulnerability affects Dell RecoverPoint for Virtual Machines versions 6.0.3 and 6.0.3.1. Systems running either of these releases are susceptible to the command injection flaw.

Risk and Exploitability

Based on the description, it is inferred that exploitation requires remote access with high privileges, which increases risk for organizations exposing the RecoverPoint management interface to untrusted networks. The CVSS score of 7.2 indicates a high severity, but the vulnerability is not listed in the CISA KEV catalog and the EPSS score indicates a 1% probability of exploitation. The attacker, upon successful exploitation, can gain complete control over the appliance, compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 20, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell security update for RecoverPoint for Virtual Machines to a version newer than 6.0.3.1 as recommended in the Dell advisory.
  • If a patch is not yet available, restrict remote access to the RecoverPoint management interface to trusted IP addresses or VPN endpoints.
  • Disable or remove any unused management ports and services on the RecoverPoint appliance to reduce the attack surface.

Generated by OpenCVE AI on August 20, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell RecoverPoint for Virtual Machines Enabling Remote Execution

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell RecoverPoint for Virtual Machines Enabling Remote Execution

Thu, 20 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell RecoverPoint for Virtual Machines 6.0.3 and 6.0.3.1

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell recoverpoint For Virtual Machines
Vendors & Products Dell
Dell recoverpoint For Virtual Machines

Wed, 19 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell RecoverPoint for Virtual Machines 6.0.3 and 6.0.3.1

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Recoverpoint For Virtual Machines
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-20T18:29:24.905Z

Reserved: 2026-01-13T18:05:59.425Z

Link: CVE-2026-23501

cve-icon Vulnrichment

Updated: 2026-08-20T18:29:22.364Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T15:16:59.270

Modified: 2026-08-20T19:16:52.130

Link: CVE-2026-23501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:30:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')