Impact
Dell ObjectScale versions prior to 4.3.0.1 contain an Uncontrolled Search Path Element vulnerability that allows a local, low‑privileged attacker to modify the search path used by the software. By inserting directory entries that precede trusted locations, an attacker can cause the system to load malicious code or override executables, leading to unauthorized execution of privileged code and a full escalation of privileges.
Affected Systems
Dell ObjectScale; any instance running a release earlier than 4.3.0.1 is susceptible to this vulnerability.
Risk and Exploitability
The vulnerability has a CVSS score of 7.3, indicating a high severity. EPSS information is not available, and the issue has not been listed in CISA’s KEV catalog. The attack requires local access and a low‑privileged user role, so while exploitation is feasible, it depends on an attacker gaining local access to the system. The combination of a high severity score and the local attack vector presents a significant risk to affected deployments.
OpenCVE Enrichment