Dell Cloud Disaster Recovery OS Command Injection Vulnerability Allowing Root Command Execution

Vulnerability

A command injection vulnerability has been identified in Dell Cloud Disaster Recovery versions prior to 19.20. This vulnerability allows a high-privileged attacker with local access to execute arbitrary commands with root privileges on the affected system.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands with root privileges, potentially allowing for full control over the affected system.

Remediation

Users can upgrade to Dell Cloud Disaster Recovery version 19.20 or later to address this vulnerability. The update is available in the Cloud Disaster Recovery Downloads Area.

Added: Sep 25, 2025, 4:29 PM
Updated: Sep 25, 2025, 4:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
2.8
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.