DSA-2026-353: Security Update for Cloud Disaster Recovery Vulnerabilities
Résumé: Cloud Disaster Recovery remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
Critical
Détails supplémentaires
This Security Advisory applies to Cloud Disaster Recovery versions 20.2 and previous.
Détails
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
|
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
9.1 |
|
|
CVE-2026-71171 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
7.2 |
|
|
CVE-2026-68865 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain Remote Code Execution vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
7.2 |
|
|
CVE-2026-71173 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Limitation of a Pathname to a Restricted Directory vulnerability. A path traversal vulnerability exists in the application due to improper validation and sanitization of user-supplied file paths. |
6.5 |
|
|
CVE-2026-71172 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
4.3 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
|
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
9.1 |
|
|
CVE-2026-71171 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
7.2 |
|
|
CVE-2026-68865 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain Remote Code Execution vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
7.2 |
|
|
CVE-2026-71173 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Limitation of a Pathname to a Restricted Directory vulnerability. A path traversal vulnerability exists in the application due to improper validation and sanitization of user-supplied file paths. |
6.5 |
|
|
CVE-2026-71172 |
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
4.3 |
Produits concernés et mesure corrective
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2026-70419, CVE-2026-71171, CVE-2026-68865, CVE-2026-71172, CVE-2026-71173 |
Dell Cloud Disaster Recovery |
Software |
Versions CDR 20.2 and prior |
Version CDR 20.3 |
|
CVEs Addressed |
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Link |
|
CVE-2026-70419, CVE-2026-71171, CVE-2026-68865, CVE-2026-71172, CVE-2026-71173 |
Dell Cloud Disaster Recovery |
Software |
Versions CDR 20.2 and prior |
Version CDR 20.3 |
Historique des révisions
|
Revision |
Date |
Description |
|
1.0 |
2026-08-24 |
Initial Release |
Remerciements
-
Dell would like to thank moonv for reporting this issue: CVE-2026-71172, CVE-2026-68865, CVE-2026-71173
-
Dell would like to thank Ahmed Y. Elmogy for reporting this issue: CVE-2026-70419
-
Dell would like to thank WinD39 for reporting this issue: CVE-2026-71171