Impact
Dell PowerProtect Cyber Recovery versions before 20.3 contain an Improper Authentication flaw that permits a low‑privileged attacker with remote access to bypass authentication controls and gain unauthorized access to protected resources.
Affected Systems
The vulnerability affects Dell PowerProtect Cyber Recovery systems deployed by Dell’s Cyber Recovery and Power Protect Cyber Recovery lines, specifically all releases prior to version 20.3.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity, although no EPSS score is available and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is remote, and the attacker only needs low privileges on the network to attempt the exploit, making it exploitable from a wide range of threat actor capabilities.
OpenCVE Enrichment