Impact
Dell PowerProtect Cyber Recovery versions earlier than 20.3 contain a flaw where the system blindly follows Unix symbolic links during file operations (CWE-61). A local attacker with limited privileges can create or modify a symlink that points at an executable or script, causing the recovery service to execute it. This injection allows the attacker to run arbitrary code with the privileges of the affected component, potentially compromising the integrity of the storage environment.
Affected Systems
The vulnerability affects Dell PowerProtect Cyber Recovery, including its Power Protect Cyber Recovery product line. All installations running any version earlier than 20.3 are vulnerable. No other Dell software is listed as impacted.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity, reflecting that exploitation requires local, non‑privileged access and is confined to the affected system. The lack of an EPSS value and absence from the CISA KEV catalogue suggest limited public exploitation activity. The attack is likely to involve local file manipulation, as remote exploitation would require additional compromise to gain local access.
OpenCVE Enrichment