Impact
The vulnerability is an improper access control flaw within Dell PowerFlex Manager. A low‑privileged attacker on an adjacent network could gain unauthorized access or elevate privileges on the affected system. This could allow compromise of confidential data, modification of configurations, or broader system control, corresponding to CWE‑284.
Affected Systems
Dell PowerFlex Manager, all current releases are affected. No specific version information is available in the advisory. The vulnerability applies to all installations where PowerFlex Manager is exposed to adjacent network traffic.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog. An attacker must have low‑privileged access on the same local network to reach PowerFlex Manager. The impact is elevation of privileges and unauthorized access. Given the moderate score and low exploitation probability, patching remains essential to prevent potential exploitation.
OpenCVE Enrichment