Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-07-22
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Dell PowerProtect Data Manager’s REST API leads to improper input validation (CWE‑20). A highly privileged attacker who can access the API remotely may exploit the vulnerability to execute arbitrary commands, potentially gaining full control over the affected system.

Affected Systems

Dell PowerProtect Data Manager versions earlier than 20.2.0.0 are affected.

Risk and Exploitability

The CVSS score of 6.7 indicates a medium‑to‑high severity, and the EPSS score of < 1% indicates a very low exploitation probability; the vulnerability is not listed in CISA KEV. If a high‑privileged attacker has remote API access, remote code execution is achievable.

Generated by OpenCVE AI on August 4, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell PowerProtect Data Manager to version 20.2.0.0 or later to apply the vendor patch.
  • Apply strict access controls so that only trusted administrators possess high‑privilege API rights.
  • Restrict network access to the REST API using firewall rules or IP whitelisting to limit exposure while monitoring for unauthorized attempts.

Generated by OpenCVE AI on August 4, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enables Remote Code Execution

Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enables Remote Code Execution

Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enables Remote Execution

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enables Remote Execution

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-24T20:12:11.641Z

Reserved: 2026-05-17T17:04:27.066Z

Link: CVE-2026-46737

cve-icon Vulnrichment

Updated: 2026-07-22T18:47:33.609Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T16:17:24.093

Modified: 2026-07-29T17:39:45.833

Link: CVE-2026-46737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation