Impact
Dell Unisphere for PowerMax contains a path traversal flaw that permits a low‑privileged attacker with remote access to read arbitrary data, such as configuration files or logs, through unauthorized file reads.
Affected Systems
Dell Unisphere for PowerMax versions 10.3.0.5 and earlier are impacted. These installations process remote file path requests without proper validation, enabling unintended file access.
Risk and Exploitability
The likely attack vector is remote access to the Unisphere interface. The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% shows a very low current likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker with low‑privileged remote access to the Unisphere interface can craft a file path to read files on the underlying host; no elevated system privileges are required, and the issue is exploitable only where the Unisphere service is exposed to network traffic.
OpenCVE Enrichment