Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-07-22
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Manager versions prior to 20.2.0.0 contain an improper input validation flaw (CWE-20) that could allow a high-privileged attacker with remote access to elevate their privileges within the system.

Affected Systems

All installations of Dell PowerProtect Data Manager running any version earlier than 20.2.0.0 are affected.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity if the flaw is exploited. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description indicates that a remote attacker possessing high-privileged access can potentially exploit the flaw, thereby gaining elevated privileges and potentially moving laterally within the environment.

Generated by OpenCVE AI on August 4, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Security Update for PowerProtect Data Manager version 20.2.0.0 or newer.
  • Restrict or audit high-privileged remote access to the PowerProtect Data Manager management interface to reduce attack opportunities.
  • Restart affected services or reboot the system to ensure the updated application components are loaded.

Generated by OpenCVE AI on August 4, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager Allows Privilege Escalation

Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Enabling Privilege Escalation in Dell PowerProtect Data Manager

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Enabling Privilege Escalation in Dell PowerProtect Data Manager

Thu, 23 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-24T03:56:05.881Z

Reserved: 2026-04-15T05:04:31.837Z

Link: CVE-2026-40714

cve-icon Vulnrichment

Updated: 2026-07-22T16:04:07.208Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T16:17:19.423

Modified: 2026-07-29T17:40:30.153

Link: CVE-2026-40714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation