Impact
Dell PowerFlex Manager versions older than 5.1.0.1 contain an Improper Neutralization of Special Elements used in an SQL Command (CWE‑‑privileged attacker who can reach the manager remotely to inject malicious SQL statements, enabling the attacker to extract sensitive data and gain unauthorized access to the system.
Affected Systems
All Dell PowerFlex Manager instances running versions earlier than 5.1.0.1 are affected; no specific sub‑versions are listed beyond the cutoff.
Risk and Exploitability
The vulnerability is assigned a CVSS score of 8.5, indicating high severity, while the EPSS score is below 1%, suggesting that widespread exploitation has not yet been observed. The flaw is not yet cataloged in the CISA KEV list. Because the attack can be performed remotely with only low privileges and requires network reachability to the management interface, the risk to confidentiality and integrity remains significant for exposed environments.
OpenCVE Enrichment