Impact
Dell PowerProtect One versions 20.1.0.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command vulnerability. This flaw can allow instructions supplied by a low privileged attacker with remote access to be executed directly on the host operating system. If successfully exploited, the attacker could run arbitrary commands with the privileges of the affected service, potentially compromising confidentiality, integrity, and availability of the entire storage system.
Affected Systems
The vulnerability impacts Dell PowerProtect One products, specifically versions 20.1.0.0 and all lower releases. All deployments using these versions are vulnerable until the security update is applied.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity flaw. The EPSS score is not available, but the vulnerability is not currently listed in CISA’s KEV catalog, suggesting it may not yet have active public exploitation. However, the flaw permits remote command execution and is exploitable by attackers who have remote access, making the risk significant for exposed or remotely reachable installations.
OpenCVE Enrichment