Impact
The vulnerability is an OS command injection caused by improper neutralization of special elements. An attacker with high privileges and remote access can exploit PowerFlex Manager during OS Repository processing to inject arbitrary commands that execute as root. If successful, this gives the attacker full control over the appliance and enables lateral movement into other managed infrastructure.
Affected Systems
Dell PowerFlex Manager versions prior to 5.1.0.1 are affected; any appliance running an affected version is vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates a severe risk, while the EPSS score of 1% suggests a low but non-zero probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is remote access to the PowerFlex Manager interface, inferred from the description, and requires high‑privileged credentials. Exploitation would lead to arbitrary root command execution, full appliance compromise, and potential lateral movement into connected infrastructure.
OpenCVE Enrichment