MEDIUM

CVE-2026-35068

Dell Powerflex Manager 2026-06-17 CVSS v3.1
CVSS
5.7

Description

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.

Summary dbcve.org

SQL injection vulnerability in Dell PowerFlex Manager allows a low-privileged attacker with adjacent network access to inject malicious SQL commands, potentially leading to unauthorized information disclosure from the database.

Mitigation

Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later to obtain the patched code that properly neutralizes special elements in SQL commands.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

0.19%
Probability of exploitation in next 30 days
9.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE