Impact
Dell PowerProtect Data Manager contains a flaw that generates incorrect security tokens within its Identity and Access Management component. The weakness, classified as CWE-1270, is an authorization inadequacy that allows an attacker with low privileges to compel the system into assigning higher‑level privileges. This can lead to unauthorized actions, data exposure, and compromise of system integrity.
Affected Systems
The vulnerability affects Dell PowerProtect Data Manager versions earlier than 20.2.0.0. No other versions or products are reported as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity rating. The EPSS score of < 1% suggests a low probability of exploitation, yet the risk remains because the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a low‑privileged attacker gaining remote access to an exposed endpoint of the IAM service and manipulating the token generation process to elevate privileges.
OpenCVE Enrichment