Impact
The vulnerability is an Exposure of Sensitive Information to an Unauthorized Actor in the REST API of Dell PowerProtect Data Manager. A high privileged attacker with local access could exploit this flaw, resulting in the unauthorized disclosure of potentially sensitive data. The weakness is classified as CWE-200, a classic information‑leak scenario.
Affected Systems
Dell PowerProtect Data Manager versions prior to 20.2.0 The REST API in those releases can leak sensitive information to attackers who possess local high‑privileged access.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, and the EPSS score is 0.00108, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV, implying it is not a known exploited vulnerability at this time. The attack vector is local with high privilege, meaning that any user who can act as a local high‑privileged user has the potential to trigger the information disclosure.
OpenCVE Enrichment