Impact
This vulnerability allows a low‑privileged attacker with remote access to send unsanitized input that is incorporated into SQL statements within Dell OpenManage Enterprise. The resulting SQL injection could be leveraged to perform script injection, potentially modifying system configuration or affecting data integrity. The impact is confined to the scope of the vulnerable application but could enable further exploitation if additional privileges are gained.
Affected Systems
Dell OpenManage Enterprise, versions prior to 4.7.0
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score is < 1%, showing a very low exploitation probability, and the vulnerability is not listed in CISA KEV. It can be exploited remotely by an attacker with low privileges, requiring only remote access to the vulnerable component. It is inferred that no public exploit is known, as no exploit is documented and the EPSS score indicates a low likelihood, and the need for connectivity to the vulnerable system reduces immediate risk, but the high CVSS score warrants timely remediation.
OpenCVE Enrichment