Description
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks.
Published: 2026-09-03
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Manager versions 20.2.0.0 and earlier contain a reliance on data/memory layout flaw that allows an unauthenticated remote attacker to manipulate memory and trigger a phishing attack. The vulnerability can be leveraged to trick users into believing they are interacting with a legitimate component, potentially leading to credential theft or further compromises. The flaw’s impact centers on confidentiality and integrity by enabling the attacker to masquerade as a trusted service.

Affected Systems

The flaw affects Dell PowerProtect Data Manager, all releases up to version 20.2.0.0. Users running these versions, regardless of install location, are vulnerable. No other Dell products are listed as affected.

Risk and Exploitability

The CVSS score of 6.8 indicates a high‑risk moderate severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The description states an unauthenticated remote attacker can exploit the flaw, suggesting the attack vector is via external network exposure. While exploit research is not publicly documented, the moderate CVSS and lack of exploitation data imply a realistic but not imminent risk, yet the potential for phishing campaigns justifies prompt remediation.

Generated by OpenCVE AI on September 3, 2026 at 13:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Manager security update described in DSA-2026-368, ensuring the installed version is newer than 20.2.0.0.
  • Restrict remote access to PowerProtect Data Manager by enforcing firewall rules or limiting management interfaces to trusted networks.
  • Enable monitoring and alerting for anomalous authentication attempts or phishing indicators, and review logs for suspicious activity.

Generated by OpenCVE AI on September 3, 2026 at 13:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Reliance on Data/Memory Layout Vulnerability in Dell PowerProtect Data Manager Allows Remote Phishing Attacks

Thu, 03 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Thu, 03 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks.
Weaknesses CWE-188
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-03T08:15:29.242Z

Reserved: 2026-07-31T17:04:55.170Z

Link: CVE-2026-68860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T13:06:01.480

Modified: 2026-09-03T13:06:01.480

Link: CVE-2026-68860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:15:04Z

Weaknesses
  • CWE-188

    Reliance on Data/Memory Layout