Impact
Dell PowerProtect One versions 20.1.0.0 and below contain an OS Command Injection vulnerability (CWE-78). An attacker with low privileges who can reach the appliance remotely could inject arbitrary commands, ultimately achieving code execution on the underlying operating system. The weakness resides in improper neutralization of special elements used in an OS command string constructed by the software.
Affected Systems
Dell PowerProtect One appliances running firmware 20.1.0.0 or earlier are affected. These are the default production devices used for data protection in enterprise environments.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating a high severity. No EPSS score is available, and the flaw is not catalogued in the CISA KEV list, but the attack vector is remote network access with low privileged credentials. An attacker could exploit this by sending specially crafted requests over the network to the appliance’s management interface, leading to unauthorized code execution.
OpenCVE Enrichment