Impact
Dell ECS and ObjectScale expose an improper privilege management flaw. A local attacker who already possesses high‑privileged access can exploit this weakness to elevate their privileges further, potentially gaining administrative control over the system. The vulnerability is a classic example of CWE‑269, where insufficient checks on permissions allow privilege escalation.
Affected Systems
Affected versions are Dell ECS releases 3.8.1.0 through 3.8.1.7 and Dell ObjectScale releases earlier than 4.4.0.0. These are identified by Dell under their ECS product line, which is used for object storage and data protection.
Risk and Exploitability
The CVSS base score of 6.7 reflects a moderate severity, and the EPSS score of less than 1 % indicates a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known large‑scale attacks have been documented. Exploitation requires local, high‑privileged access, so the attack vector is local. Because the required access is already privileged, the risk lies in an attacker extending that control to obtain full system authority.
OpenCVE Enrichment