Description
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Severity (CVSS)
| Base score | 7.7 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| Provided by | CNA |
Weaknesses
- CWE-89 — CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Dell | PowerFlex Manager | 0 to <5.1.0.1 or later; 0 to <4.5.5.2 or later |
References
Generated from the official CVE List on 11 Jul 2026 07:02 UTC.