Dell Storage Center - Dell Storage Manager Command Injection Vulnerability Allowing Remote Execution

Vulnerability

A command injection vulnerability has been identified in Dell Storage Center - Dell Storage Manager, version 20.1.20. This vulnerability arises from improper neutralization of special elements used in commands, allowing a low-privileged attacker with adjacent network access to potentially exploit the issue and execute commands remotely.

Impact

Exploitation of this vulnerability could lead to unauthorized remote execution of commands on the affected system.

Remediation

Users are advised to update to Dell Storage Manager version 2020 R1.21 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.