Impact
A user with low privileges can exploit an incorrect authorization flaw in the REST API of Dell PowerProtect Data Manager. The vulnerability, identified as CWE‑863, allows an attacker to bypass configured protection mechanisms, potentially leading to unauthorized data access or manipulation.
Affected Systems
Dell PowerProtect Data Manager software, specifically versions 20.2.0.0 and earlier, are affected by this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The absence of an EPSS score and the fact that it is not listed in the CISA KEV catalog suggest that the likelihood of exploitation is currently uncertain, though not zero. The attack vector is likely remote over the exposed REST API; a low‑privileged user could craft requests that circumvent normal access checks to achieve privilege escalation and bypass protection controls.
OpenCVE Enrichment