MEDIUM
CVE-2026-35068
CVSS
5.7
Description
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.
Summary dbcve.org
SQL injection vulnerability in Dell PowerFlex Manager allows a low-privileged attacker with adjacent network access to inject malicious SQL commands, potentially leading to unauthorized information disclosure from the database.
Mitigation
Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later to obtain the patched code that properly neutralizes special elements in SQL commands.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
0.19%
Probability of exploitation in next 30 days
9.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.