Impact
Dell Repository Manager versions before 3.5.2 contain an Incorrect Default Permissions weakness that allows a low privileged attacker with remote access to gain higher privileges. The vulnerability arises from permissions that are set too permissively by default, letting an attacker perform actions that should require administrative rights, thereby violating confidentiality and integrity of stored artifacts.
Affected Systems
The affected product is Dell Repository Manager, provided by Dell. All installations running a version earlier than 3.5.2 are impacted. Users should verify the exact version and apply updates when available.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access by a low privileged user. If exploited, the adversary can elevate privileges within the Repository Manager environment, potentially affecting all artifacts and users within that system.
OpenCVE Enrichment