Impact
Dell PowerProtect Data Manager versions earlier than 20.2.0.0 contain an improper input validation weakness in the REST API, allowing a remote attacker who already has high‑privileged credentials to supply crafted parameters that the system accepts without adequate checks. This flaw can be leveraged to obtain higher privileges within the appliance, potentially granting full administrative control. The weakness is identified as CWE‑20: Improper Input Validation.
Affected Systems
All Dell PowerProtect Data Manager appliances running software revision 20.2.0.0 or earlier are affected. The vulnerability targets the REST API interface exposed by the appliance, meaning any system running the vulnerable version is exposed until a patch or upgrade is applied.
Risk and Exploitability
The CVSS base score of 9.1 marks this issue as critical, and the EPSS score of less than 1% indicates a very low overall likelihood of exploitation in the wild, though targeted attacks could still occur. Because the flaw is accessed remotely via the REST API and requires high‑privileged credentials, the attack surface remains limited to those with legitimate administrative access. While the vulnerability is not yet listed in the CISA KEV catalog, it poses a significant risk to affected enterprises, especially if their API endpoints are reachable from untrusted networks.
OpenCVE Enrichment