Impact
Dell Virtual Storage Integrator for VMware vSphere Client prior to version 10.11.1.0 contains an OS Command Injection flaw in the IAPI component. An unauthenticated attacker who can reach the component can execute arbitrary operating system commands with root privileges. This leads to full control over the VSI appliance and potentially the underlying host, compromising confidentiality, integrity, and availability of the entire deployment. The vulnerability is categorized as CWE‑78 – OS Command Injection.
Affected Systems
Products affected are Dell Virtual Storage Integrator for VMware vSphere Client with versions earlier than 10.11.1.0. The specific vendor is Dell and the product name is Virtual Storage Integrator for VMware vSphere Client. Users of earlier builds must verify whether they are running a vulnerable version and plan for an upgrade.
Risk and Exploitability
Based on the description, the likely attack vector is a remote, unauthenticated connection to the IAPI endpoint. The CVSS score of 9.8 indicates critical severity, but the EPSS score of 2% suggests a low probability of exploitation in the wild. Although the vulnerability allows an attacker to execute arbitrary commands as root once accessed, the lack of an authentication requirement and the remote nature do not guarantee immediate exploitation; it requires the component to be exposed to an untrusted network. The vulnerability is not listed in the CISA KEV catalog, but the potential impact warrants close monitoring. An attacker can exploit the flaw by sending crafted requests to the IAPI endpoint, but the low EPSS indicates that such exploitation is unlikely unless the system is directly reachable from untrusted sources.
OpenCVE Enrichment