Sceawere
Vulnerability Detail
CVE-2026-23501UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell RecoverPoint for VMs OS Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- Dell
- Product
- RecoverPoint for Virtual Machines
- Attack Type
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-08-19T15:16:59.270Z",
"pubdate": "2026-08-19T15:16:59.270Z",
"executiveSummary": "Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, is affected by an Improper Neutralization of Special Elements used in an OS Command vulnerability, commonly categorized as OS Command Injection.\nThis security flaw allows a remote attacker to achieve arbitrary command execution on the underlying operating system of the targeted system.\nThe vulnerability specifically impacts Dell RecoverPoint for VMs across the specified version numbers, posing significant risk implications regarding confidentiality, integrity, and availability of the host environment.\nSuccessful exploitation of this flaw requires high privileges and remote access to the vulnerable system.\nGiven the severity of command execution vulnerabilities, unauthorized execution of system-level instructions by a privileged adversary can lead to total system compromise, unauthorized data access, and disruption of critical business continuity and disaster recovery operations managed by the product.",
"technicalDetails": "The root cause of the vulnerability stems from improper input validation and insufficient sanitization of special characters used in operating system commands within Dell RecoverPoint for VMs versions 6.0.3 and 6.0.3.1.\nWhen input containing malicious shell metacharacters is processed by the vulnerable component without adequate neutralization, the underlying operating system interprets the injected input as executable command instructions rather than static data parameters.\nExploitation of this vulnerability requires remote network access to the target product alongside high-level administrative or system privileges.\nAn authenticated attacker possessing the requisite high-level privileges can craft a specialized payload containing arbitrary OS commands and submit it to the vulnerable interface.\nThe attack flow proceeds as follows: the attacker establishes a remote connection to the vulnerable Dell RecoverPoint for VMs instance, authenticates with high privileges, and delivers the malicious payload to the affected component.\nUpon receiving the input, the application fails to sanitize special elements, passing the unsanitized string directly to the underlying system shell for execution.\nThe payload executes with the privilege level of the application process, which typically possesses elevated permissions.\nPost-exploitation impact includes full system compromise, execution of arbitrary binaries, manipulation of system configurations, access to sensitive data, and potential lateral movement within the network infrastructure reliant on the affected disaster recovery solution."
}