Impact
Dell PowerProtect Cyber Recovery, versions 20.2 and earlier, have a SQL injection flaw classified as Improper Neutralization of Special Elements used in an SQL Command (CWE-89). The flaw allows an attacker with low privileges and remote access to supply malicious input that is incorporated into database queries, potentially exposing sensitive data stored in the backend. This type of vulnerability can lead to the compromise of confidential information without affecting system availability or integrity directly.
Affected Systems
The affected products are Dell PowerProtect Cyber Recovery and Dell Cyber Recovery. The vulnerability exists in all releases version 20.2 and older, including all earlier patch levels of these products.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, reflecting the possibility of data exposure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access and a low privileged user account; therefore, the likely vector is a remote network connection. Once exploited, the attacker could retrieve data from the database, but the vulnerability does not provide direct code execution or denial of service capabilities.
OpenCVE Enrichment