Impact
A stack buffer overflow exists in the file‑level restore agent component of Dell PowerProtect Data Manager. This flaw can allow a high‑privileged remote attacker to read sensitive data from the system. The weakness is a classic memory corruption issue (overflow) that may expose confidential information without affecting the integrity of the data. The attack does not provide a direct remote code execution path, but the leakage of internal data could be used in further attacks or for reconnaissance.
Affected Systems
Dell PowerProtect Data Manager versions 20.2.0.0 and any earlier releases are affected. The vulnerability lies within the file‑level restore agent service that performs restore operations for stored data, and it has been identified specifically for these product versions.
Risk and Exploitability
The CVSS score of 7.8 places the flaw in the high‑severity range, indicating significant risk when the conditions are met. Although the EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests no current widespread exploitation. The vulnerability requires remote access and high privileges to achieve exploitation, so the likelihood of successful attacks depends on the attacker’s privilege level. Nevertheless, if an attacker gains the necessary access, they could gain confidential data from the protected storage system.
OpenCVE Enrichment