Impact
Dell PowerProtect Data Manager versions 20.2.0.0 and earlier contain a reliance on data/memory layout flaw that allows an unauthenticated remote attacker to manipulate memory and trigger a phishing attack. The vulnerability can be leveraged to trick users into believing they are interacting with a legitimate component, potentially leading to credential theft or further compromises. The flaw’s impact centers on confidentiality and integrity by enabling the attacker to masquerade as a trusted service.
Affected Systems
The flaw affects Dell PowerProtect Data Manager, all releases up to version 20.2.0.0. Users running these versions, regardless of install location, are vulnerable. No other Dell products are listed as affected.
Risk and Exploitability
The CVSS score of 6.8 indicates a high‑risk moderate severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The description states an unauthenticated remote attacker can exploit the flaw, suggesting the attack vector is via external network exposure. While exploit research is not publicly documented, the moderate CVSS and lack of exploitation data imply a realistic but not imminent risk, yet the potential for phishing campaigns justifies prompt remediation.
OpenCVE Enrichment