CVE-2026-74770

8.8

Dell · PowerProtect One

Dell PowerProtect One is susceptible to an OS command injection vulnerability, allowing authenticated, low-privileged remote attackers to execute arbitrary code.

Executive summary

A critical OS command injection vulnerability in Dell PowerProtect One allows remote attackers with low-level privileges to achieve arbitrary code execution.

Vulnerability

This vulnerability, identified as CWE-78, involves the improper neutralization of special elements used in an OS command. The flaw enables an attacker with low-level user privileges to execute arbitrary commands remotely on the underlying host system.

Business impact

The ability to execute arbitrary OS commands poses a severe risk to organizational infrastructure, as it grants attackers the potential to gain full control over the backup appliance. Given the CVSS score of 8.8, this vulnerability presents a high risk of data exfiltration, service disruption, and lateral movement within the network. Compromise of backup systems is particularly dangerous, as it may allow attackers to delete or modify historical data, significantly impeding disaster recovery capabilities.

Remediation

Immediate Action: Upgrade all instances of Dell PowerProtect One to version 20.3.0.0 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system access logs for anomalous command execution patterns or unauthorized shell activity originating from low-privileged service accounts.

Compensating Controls: Implement strict network segmentation to limit access to the management interface of the PowerProtect One appliance to only trusted administrative subnets.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this command injection vulnerability necessitates an immediate response. Administrators should prioritize patching the affected PowerProtect One appliances to version 20.3.0.0 to eliminate the remote code execution vector. Failure to address this flaw could lead to a complete compromise of critical backup infrastructure, creating significant operational and security risks.

More Dell CVEs

Sources