Dell Cloud Disaster Recovery 20.2 及更早版本存在一个“操作系统命令中特殊元素未正确中和”(即 OS 命令注入)漏洞。具有高权限且具备远程访问能力的攻击者可能利用该漏洞,进而实现任意命令执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | Cloud Disaster Recovery | < CDR 20.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell | Cloud Disaster Recovery | 0 ~ CDR 20.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68861 | 8.8 HIGH | Dell PowerProtect One 20.1.0.0 OS命令注入漏洞 |
| CVE-2026-74770 | 8.8 HIGH | Dell PowerProtect One 20.1.0.0 及之前版本 OS命令注入漏洞 |
| CVE-2026-79938 | 7.6 HIGH | Dell PowerProtect Cyber Recovery 20.3前版本认证缺陷 |
| CVE-2026-68863 | 7.5 HIGH | Dell PowerProtect One 20.1.0.0以下栈溢出致DoS |
| CVE-2026-71171 | 7.2 HIGH | Dell Cloud DR 20.2以下OS命令注入漏洞 |
| CVE-2026-74771 | 6.5 MEDIUM | Dell PowerProtect One 20.1.0及以下用户可控密钥认证绕过 |
| CVE-2026-49809 | 6.5 MEDIUM | Dell PowerProtect Cyber Recovery 20.2 及之前版本SQL注入 |
| CVE-2026-79940 | 5.9 MEDIUM | iDRAC9 7.00.00.182/7.20.30.50前版本访问控制漏洞 |
| CVE-2026-74774 | 5.9 MEDIUM | Dell PowerProtect One 20.1.0.0 及更早版本证书验证缺陷 |
| CVE-2026-79939 | 5.8 MEDIUM | Dell PowerProtect 20.3前符号链接跟踪致脚本注入 |
| CVE-2026-67275 | 5.3 MEDIUM | Dell PowerProtect One 20.1.0 及之前版本缓存投毒 |
| CVE-2026-71172 | 4.3 MEDIUM | Dell Cloud DR 20.2前版本SSRF漏洞 |
No comments yet