Impact
Dell ObjectScale versions prior to 4.3.0.1 contain a path traversal vulnerability (CWE-35). A low‑privileged local attacker could traverse directory boundaries to access or modify files, potentially tampering with sensitive data. The flaw enables modification of configuration or data files, undermining integrity.
Affected Systems
Dell ObjectScale, versions before 4.3.0.1, is affected. No specific CPE listed; the vulnerability affects all installations of that product.
Risk and Exploitability
The CVSS score is 7.1, indicating a high impact. The EPSS score is unknown and the vulnerability is not in CISA KEV. Local access with low privileges is required; the attacker must be able to login locally or have a compromised account. The path traversal can be leveraged to tamper with data, though this requires local privilege.
OpenCVE Enrichment