Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity (CVSS)
| Base score | 8.8 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Provided by | CNA |
Weaknesses
- CWE-1270 — CWE-1270: Generation of Incorrect Security Tokens
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Dell | PowerProtect Data Manager | 0 to <20.2.0.0 or later |
References
Generated from the official CVE List on 23 Jul 2026 07:04 UTC.