Impact
Dell PowerFlex Manager contains an SQL injection flaw that allows a low‑privileged attacker with network access adjacent to the manager to inject malicious SQL commands. The weakness is an improper neutralization of special elements used in an SQL command, classified as CWE‑89. Exploitation of this flaw can lead to the disclosure of sensitive data stored in the PowerFlex database, potentially exposing configuration details, user credentials, or other confidential information.
Affected Systems
Only Dell PowerFlex Manager is affected. The exact version range is not enumerated in the advisory; the issue exists in those releases identified by Dell as vulnerable during the security update.
Risk and Exploitability
The CVSS score of 3.5 indicates a low impact on confidentiality and integrity when the vulnerability is abused. The EPSS score is under 1%, which suggests that active exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, and the attack requires the attacker to already have a low level of privilege within the network segment that can reach PowerFlex Manager. The potential impact remains limited to data disclosure rather than remote code execution or denial of service.
OpenCVE Enrichment