Impact
Dell PowerFlex Manager contains an improper neutralization of special SQL elements, creating a classic SQL injection flaw (CWE‑89). An attacker with low‑privileged access that can reach the manager remotely may inject SQL and read data from the underlying database, potentially exposing sensitive information. The vulnerability does not grant arbitrary code execution or administrator privileges, but it does permit read‑only disclosure of protected data.
Affected Systems
Dell PowerFlex Manager versions earlier than 5.1.0.1 are affected. No other vendors or product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.7 classifies the flaw as a high‑severity issue, while the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring only a low‑privileged account. Although the flaw does not allow code execution, the resulting information exposure can have serious business and compliance consequences.
OpenCVE Enrichment