Impact
A flaw in Dell PowerProtect Data Manager’s REST API leads to improper input validation (CWE‑20). A highly privileged attacker who can access the API remotely may exploit the vulnerability to execute arbitrary commands, potentially gaining full control over the affected system.
Affected Systems
Dell PowerProtect Data Manager versions earlier than 20.2.0.0 are affected.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium‑to‑high severity, and the EPSS score of < 1% indicates a very low exploitation probability; the vulnerability is not listed in CISA KEV. If a high‑privileged attacker has remote API access, remote code execution is achievable.
OpenCVE Enrichment