← Terug naar overzicht

Dell Cloud Disaster Recovery versions 20.2 and prior contain an OS Command Injection vulnerability (CVE-2026-70419). The flaw is classified as Improper Neutralization of Special Elements used in an OS Command. A high privileged attacker with remote access could exploit this vulnerability to execute arbitrary commands on the affected system. Dell has issued a security advisory (DSA-2026-353) addressing this vulnerability. Users are advised to update to a patched version beyond 20.2 to mitigate the risk. The vulnerability poses a significant risk due to the potential for remote command execution in disaster recovery infrastructure.

Affected products

  • Dell Cloud Disaster Recovery 20.2 and prior

Related CVE's

  • CVE-2026-70419

Categories

  • Cloud & Virtualization
  • Enterprise Applications