Impact
Dell SmartFabric Manager exposes a weakness where insufficient permissions are not properly checked, allowing an attacker with low-level access to read sensitive data. This Improper Handling of Insufficient Permissions or Privileges flaw (CWE-280) can lead to information disclosure without causing denial of service or code execution.
Affected Systems
The vulnerability affects Dell SmartFabric Manager versions earlier than 2.2.1. Any deployment running a pre‑2.2.1 build is susceptible, regardless of environment.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity level. No EPSS value is available and the issue is not listed in CISA KEV. A likely attack requires the attacker to have remote connectivity to the SmartFabric Manager service and to operate with low privileges; from that position they can trigger the flaw and retrieve data. The likelihood of exploitation is considered low, but the potential for confidential data exposure remains.
OpenCVE Enrichment