Impact
Dell ObjectScale prior to 4.3.0.1 contains an improper neutralization of special elements in OS command construction, enabling a local attacker with low privileges to inject operating system commands. Exploiting this vulnerability can lead to privilege escalation, granting the attacker elevated rights on the affected system. The CVSS score of 7.8 highlights a high severity risk for confidentiality and integrity beyond the authenticated user.
Affected Systems
The vulnerability affects Dell ObjectScale deployments running any version earlier than 4.3.0.1. Systems using those versions are susceptible to command injection via local interfaces that lack proper input sanitization. No specific firmware or component details are supplied in the advisory beyond the product name.
Risk and Exploitability
The risk is moderate to high with a CVSS value of 7.8. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. However, the attack vector is local and requires a low privileged user, implying that anyone with local access can attempt exploitation. The potential impact is significant due to the possibility of up to full system compromise through privilege escalation.
OpenCVE Enrichment