Description
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Published: 2026-08-26
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Cloud Disaster Recovery versions 20.2 and prior contain a Server‑Side Request Forgery (SSRF) flaw. An attacker with a low‑privilege account that can reach the service may direct the server to fetch arbitrary internal resources. The impact is the ability to read or potentially alter data inside the private network, including credentials or configuration files. The weakness is classified under CWE‑918, indicating a failure to validate or restrict outbound requests.

Affected Systems

The vulnerability applies to Dell: Cloud Disaster Recovery, specifically all releases up to and including version 20.2.

Risk and Exploitability

The CVSS score of 4.3 denotes moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation reports. Likely vectors are remote attackers who can authenticate with weak privileges; exploitation requires network access to the Cloud Disaster Recovery instance and the ability to craft requests to the server. Once exploited, the attacker could both view internal resources and potentially influence system behavior through crafted requests.

Generated by OpenCVE AI on August 26, 2026 at 21:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s latest security update for Cloud Disaster Recovery to remove versions 20.2 or earlier.
  • Limit network exposure by allowing only trusted IP addresses and privileged users to access the Cloud Disaster Recovery service, and restrict outbound traffic from the service to essential destinations.
  • Implement network monitoring to detect unusual outbound requests from the Cloud Disaster Recovery environment that could indicate SSRF activity.

Generated by OpenCVE AI on August 26, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Dell Cloud Disaster Recovery versions 20.2 and earlier

Wed, 26 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell cloud Disaster Recovery
Vendors & Products Dell
Dell cloud Disaster Recovery

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Cloud Disaster Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T19:46:12.189Z

Reserved: 2026-08-04T23:04:32.436Z

Link: CVE-2026-71172

cve-icon Vulnrichment

Updated: 2026-08-26T19:46:05.660Z

cve-icon NVD

Status : Received

Published: 2026-08-26T20:17:59.120

Modified: 2026-08-26T20:17:59.120

Link: CVE-2026-71172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)