Impact
Dell PowerProtect One versions 20.1.0.0 and earlier contain a certificate validation flaw (CWE‑295). An unauthenticated remote attacker could present a forged or self‑signed certificate, causing the system to accept the connection and bypass its built‑in protection mechanisms. This could lead to unauthorized access to protected data or operational control depending on the stored assets and configuration.
Affected Systems
The vulnerability affects Dell PowerProtect One 20.1.0.0 and all previous releases. No other vendors or products were identified in the CNA data.
Risk and Exploitability
The CVSS base score is 5.9, indicating moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Attackers would need remote network access and the ability to provide a certificate to the target. Given the CVSS rating, the risk is non‑critical but still significant, and the attack vector is remote with no authentication required.
OpenCVE Enrichment