Impact
This vulnerability is a Deserialization of Untrusted Data flaw that allows an attacker to supply crafted data that is processed by Dell ObjectScale. A successfully exploited instance can execute arbitrary code on the host and compromise the confidentiality, integrity, and availability of the affected system. The flaw stems from insecure handling of object serialization during remote service calls, resulting in unchecked execution of malicious input.
Affected Systems
Dell ObjectScale systems running versions earlier than 4.4.0.0 are affected. These versions expose a deserialization endpoint that accepts untrusted data from remote clients.
Risk and Exploitability
The CVSS score of 10 denotes the highest severity, indicating that exploitation would lead to full compromise if a flaw is triggered. However, the EPSS score is less than 1 percent, implying that, as of the last assessment, the likelihood of seeing real‑world exploitation is very low. The vulnerability is not listed in CISA's KEV catalog. Attackers may remotely exploit it without authentication, using the exposed service endpoints, and are likely to rely on network connectivity to the ObjectScale instance.
OpenCVE Enrichment