Impact
Dell Cloud Disaster Recovery versions 20.2 and prior contain a Server‑Side Request Forgery (SSRF) flaw. An attacker with a low‑privilege account that can reach the service may direct the server to fetch arbitrary internal resources. The impact is the ability to read or potentially alter data inside the private network, including credentials or configuration files. The weakness is classified under CWE‑918, indicating a failure to validate or restrict outbound requests.
Affected Systems
The vulnerability applies to Dell: Cloud Disaster Recovery, specifically all releases up to and including version 20.2.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation reports. Likely vectors are remote attackers who can authenticate with weak privileges; exploitation requires network access to the Cloud Disaster Recovery instance and the ability to craft requests to the server. Once exploited, the attacker could both view internal resources and potentially influence system behavior through crafted requests.
OpenCVE Enrichment