Impact
Dell Cloud Disaster Recovery 20.2 and earlier contain an OS Command Injection flaw that allows an attacker with high privileges and remote access to inject arbitrary operating system commands. The deficiency stems from improper neutralization of special elements used in a system command, which could let the attacker execute arbitrary code and compromise the confidentiality, integrity, and availability of the affected deployment.
Affected Systems
Dell Cloud Disaster Recovery 20.2 and all earlier releases are impacted. The vulnerability applies to the entire product where remote management interfaces are exposed.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity of the flaw. The EPSS score is not available, so the exploitation probability cannot be quantified from that metric. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a remote attacker with sufficient privileges who can access the management interface, potentially exploiting the flaw over the network. Exploitation would grant the attacker complete command execution capabilities on the underlying host.
OpenCVE Enrichment