Impact
Dell Unisphere for PowerMax, versions 10.3.0.5 and earlier have a flaw, a Deserialization of Untrusted Data vulnerability (CWE‑502), that allows deserialization of untrusted data. If a low-privileged user can reach the Vulnerability endpoint remotely, the attacker can trigger the flaw and run arbitrary commands with system root rights.
Affected Systems
The vulnerability affects Dell Unisphere for PowerMax appliances running version 10.3.0.5 and prior.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% points to a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access by a low‑privileged user who can invoke the deserialization process to gain root privilege.
OpenCVE Enrichment