Impact
The vulnerability is an OS Command Injection flaw (CWE‑78) that allows a low‑privileged attacker with local access to execute arbitrary operating‑system commands. The exploitation would compromise the confidentiality, integrity, and availability of the affected system by enabling unauthorized command execution.
Affected Systems
Dell ObjectScale versions prior to 4.3.0.1 are affected. All releases before the 4.3.0.1 update contain the vulnerability and are therefore vulnerable.
Risk and Exploitability
The CVSS score of 7.3 classifies this flaw as high risk. While EPSS data is not available, the flaw currently is not listed in the CISA KEV catalog. Exploitation requires local access and a low‑privileged account, indicating that the attack surface is restricted to individuals with physical or local network presence on the system.
OpenCVE Enrichment