Impact
The vulnerability is an Authorization Bypass Through User-Controlled Key that allows a low‑privileged attacker with remote access to alter data stored by Dell PowerProtect One. This flaw is a CWE‑639 weakness in authorization mechanisms and could lead to unauthorized modification of backup data.
Affected Systems
Dell PowerProtect One, versions 20.1.0.0 and earlier, are affected. The flaw can be exercised by an attacker with local privileges on a remote‑connected system that manages the backup service.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity and the EPSS score is not available, so no estimation of exploitation probability can be made. The vulnerability is not listed in CISA KEV, suggesting it has not yet been widely observed in the wild. Attack requires remote access and low privilege, making it accessible to anyone who can reach the PowerProtect One management interface. Mitigation is urgent to prevent potential tampering of backup data.
OpenCVE Enrichment