DSA-2026-353: Security Update for Cloud Disaster Recovery Vulnerabilities 

Resumo: Cloud Disaster Recovery remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Este artigo aplica-se a Este artigo não se aplica a Este artigo não está vinculado a nenhum produto específico. Nem todas as versões do produto estão identificadas neste artigo.

Impacto

Critical

Detalhes adicionais

This Security Advisory applies to Cloud Disaster Recovery versions 20.2 and previous.

Dados

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

 
CVE-2026-70419

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

9.1

CVE-2026-71171

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

7.2

CVE-2026-68865

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain Remote Code Execution vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

7.2

CVE-2026-71173

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Limitation of a Pathname to a Restricted Directory vulnerability. A path traversal vulnerability exists in the application due to improper validation and sanitization of user-supplied file paths.

6.5

CVE-2026-71172

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

4.3



Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

 
CVE-2026-70419

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

9.1

CVE-2026-71171

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

7.2

CVE-2026-68865

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain Remote Code Execution vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

7.2

CVE-2026-71173

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Limitation of a Pathname to a Restricted Directory vulnerability. A path traversal vulnerability exists in the application due to improper validation and sanitization of user-supplied file paths.

6.5

CVE-2026-71172

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

4.3



A Dell Technologies recomenda que todos os clientes levem em consideração a pontuação base CVSS e as pontuações temporais e ambientais pertinentes que possam afetar a gravidade potencial associada a uma vulnerabilidade de segurança específica.

Produtos afetados e soluções

CVEs Addressed

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

CVE-2026-70419, CVE-2026-71171, CVE-2026-68865, CVE-2026-71172, CVE-2026-71173

Dell Cloud Disaster Recovery

 Software

Versions CDR 20.2 and prior

Version CDR 20.3

 

CVEs Addressed

Product

Software/Firmware

Affected Versions

Remediated Versions

Link

CVE-2026-70419, CVE-2026-71171, CVE-2026-68865, CVE-2026-71172, CVE-2026-71173

Dell Cloud Disaster Recovery

 Software

Versions CDR 20.2 and prior

Version CDR 20.3

 

Histórico de revisão

Revision

Date

Description

1.0

2026-08-24

Initial Release

 

Agradecimentos

  • Dell would like to thank moonv for reporting this issue: CVE-2026-71172, CVE-2026-68865, CVE-2026-71173

  • Dell would like to thank Ahmed Y. Elmogy for reporting this issue: CVE-2026-70419

  • Dell would like to thank WinD39 for reporting this issue: CVE-2026-71171

 

Informações relacionadas

Produtos afetados

Cloud Disaster Recovery
Propriedades do artigo
Número do artigo: 000500898
Tipo de artigo: Dell Security Advisory
Último modificado: 24 ago. 2026
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.