Impact
Dell ObjectScale versions before 4.3.0.1 contain a path traversal flaw that allows a low‑privileged local attacker to read files outside the intended directories, potentially exposing sensitive data such as configuration files or credentials.
Affected Systems
The vulnerability affects Dell ObjectScale deployments running any version prior to 4.3.0.1. Updating to 4.3.0.1 or later removes the flaw.
Risk and Exploitability
The CVSS score of 3.3 reflects a low‑severity risk. Because the vulnerability requires local access at a privilege level below that of a system administrator, it is not exploitable over the network. No EPSS data is available and the issue is not listed in CISA KEV, indicating there are currently no public exploits or widespread active attacks reported.
OpenCVE Enrichment