Impact
The vulnerability is an improper input validation flaw (CWE-20) that allows a remote attacker with high privileges to send crafted input to the REST API, potentially enabling elevation of privileges.
Affected Systems
Dell PowerProtect Data Manager versions prior to 20.2.0.0 are affected. The flaw exists within the REST API component of the product.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical level of severity for privilege escalation. The EPSS score of <1% shows a low probability of exploitation, and the vulnerability is not listed in CISA KEV. Exploitation requires remote network access to the REST API and high‑privileged accounts; if the API is exposed to potential adversaries, the flaw poses a system‑wide risk.
OpenCVE Enrichment