Impact
Dell PowerProtect Data Manager versions prior to 20.2.0.0 contain an improper input validation flaw (CWE-20) that could allow a high-privileged attacker with remote access to elevate their privileges within the system.
Affected Systems
All installations of Dell PowerProtect Data Manager running any version earlier than 20.2.0.0 are affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity if the flaw is exploited. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description indicates that a remote attacker possessing high-privileged access can potentially exploit the flaw, thereby gaining elevated privileges and potentially moving laterally within the environment.
OpenCVE Enrichment