Threat Advisory

Dell Cloud Disaster Recovery Vulnerabilities Expose Networks to Attacks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Dell Cloud Disaster Recovery (CDR) is affected by multiple security vulnerabilities that could allow privileged attackers to execute arbitrary commands, perform remote code execution, and abuse server-side request functionality. The vulnerabilities impact Dell Cloud Disaster Recovery versions 20.2 and earlier, including critical and high-severity flaws caused by improper neutralization of special elements in OS commands and REST API components, along with an SSRF vulnerability. Successful exploitation could compromise system confidentiality, integrity, and availability by allowing attackers to execute commands or access unintended internal resources.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Dell Cloud Disaster Recovery (CDR) is affected by multiple security vulnerabilities that could allow privileged attackers to execute arbitrary commands, perform remote code execution, and abuse server-side request functionality. The vulnerabilities impact Dell Cloud Disaster Recovery versions 20.2 and earlier, including critical and high-severity flaws caused by improper neutralization of special elements in OS commands and REST API components, along with an SSRF vulnerability. Successful exploitation could compromise system confidentiality, integrity, and availability by allowing attackers to execute commands or access unintended internal resources.[emaillocker id="1283"]

CVE-2026-70419 (CVSS 9.1 — Critical): Dell Cloud Disaster Recovery contains an OS Command Injection vulnerability that allows a high-privileged remote attacker to execute commands on the affected system

CVE-2026-71171 (CVSS 7.2 — High): Dell Cloud Disaster Recovery contains an OS Command Injection vulnerability in the REST API that allows a high-privileged remote attacker to execute commands remotely on the affected system.

CVE-2026-68865 (CVSS 7.2 — High): Dell Cloud Disaster Recovery contains a Remote Code Execution vulnerability that allows an elevated-access external attacker to execute arbitrary code on the affected system.

CVE-2026-71173 (CVSS 6.5 — Medium): Dell Cloud Disaster Recovery contains a Path Traversal vulnerability that allows an elevated-access attacker with remote access to exploit improper file path validation and potentially access restricted directories or files.

CVE-2026-71172 (CVSS 4.3 — Medium): Dell Cloud Disaster Recovery contains a Server-Side Request Forgery (SSRF) vulnerability that allows a low-access external attacker to perform server-side requests through the affected system.

RECOMMENDATIONS:

  • We recommend you to update Dell Cloud Disaster Recovery to version 20.3 or later.

 

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/dell-cloud-disaster-recovery-vulnerabilities/

[/emaillocker]
crossmenu