Impact
Dell PowerProtect Data Manager versions 20.2.0.0 and earlier contain a server-side request forgery flaw in the REST API. An attacker with high privileges could exploit this SSRF to cause the system to make arbitrary outbound HTTP requests, enabling the attacker to read sensitive internal resources or data. This vulnerability can lead to the disclosure of confidential information.
Affected Systems
The affected product is Dell PowerProtect Data Manager. Versions 20.2.0.0 and all earlier releases are vulnerable. The vulnerability manifests in the API layer that handles administrative requests, and any deployment running these software versions is at risk.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate impact, but the exploit requires high privileges and a remote attacker can reach the vulnerable API. EPSS data is not available and the vulnerability is not listed in the KEV catalog, suggesting no known widespread exploitation yet. However, the SSRF weakness (CWE-918) can be leveraged in complex network environments, so systems should apply the Dell DSA-2026-368 update promptly.
OpenCVE Enrichment