Impact
This vulnerability is an OS Command Injection flaw (CWE‑78) in the REST API of Dell Cloud Disaster Recovery, rated with a CVSS score of 7.2 – indicating a high severity problem. An attacker with sufficient privileges who can reach the exposed API can inject arbitrary operating‑system commands and execute them, leading to remote code execution on the affected server. The description states that a high‑privileged attacker with remote access could potentially exploit the flaw, and the risk materializes as the possibility of insider or compromised admin credentials.
Affected Systems
Dell Cloud Disaster Recovery versions 20.2 and all older releases are vulnerable. The flaw exists in the REST API surface that becomes available when the product is deployed, and it can be triggered on any affected installation that exposes the API to a network path, whether within a corporate LAN or over a public endpoint.
Risk and Exploitability
The CVSS of 7.2 reflects the confluence of high impact (remote execution) and the need for high‑privileged credentials. EPSS data is not available, yet the requirement for elevated access and remote API exposure limits the attacker pool to individuals with prior compromise or privileged accounts. Based on the description that a high privileged attacker is required, it is inferred that valid credentials with sufficient privileges are needed for exploitation. Because the flaw is not listed in the CISA KEV catalog, there are no known widespread exploits yet, but the high severity rating and remote nature of the attack vector justify immediate mitigation actions.
OpenCVE Enrichment