CVE-2026-79939
5.8
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Summary
Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | Power Protect Cyber Recovery | 0 < 20.3.0.0 | affected |
| Dell | Cyber Recovery | 0 < osupdate-15.4.0-19.bin | affected |
| Dell | Cyber Recovery | 0 < osupdate-15.6.1-1.bin | affected |
Weaknesses
- CWE-61: CWE-61: UNIX Symbolic Link (Symlink) Following
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.