Impact
Dell Unisphere for PowerMax versions 10.2 contain a relative path traversal flaw that allows an attacker with low privileges and remote access to request paths that traverse directories outside the intended scope. By exploiting this weakness, the attacker can read or write arbitrary files on the underlying system, leading to unauthorized modification of critical system files. The vulnerability is classified as CWE-23 and carries a CVSS score of 8.1.
Affected Systems
The affected components are Dell PowerMax and Dell Unisphere for PowerMax, specifically version 10.2 and the EEM module used by Unisphere for PowerMax. Any environment running these versions without the security update is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is reported as less than 1%, showing that the probability of real‑world exploitation is currently very low, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation by a low privileged user who can send crafted requests to the Unisphere service. In absence of additional exploitation conditions, the flaw could be leveraged by anyone able to reach the Unisphere portal over the network.
OpenCVE Enrichment