Impact
This vulnerability arises from an improper neutralization of special elements used in an OS command, allowing an attacker with high privileges and remote access to inject arbitrary commands for command execution on the target system.
Affected Systems
Dell PowerProtect Data Domain is affected. through 8.7 inclusive, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain the flaw.
Risk and Exploitability
The CVSS score of 6.5. EPSS score of 1% reflects a low‑to‑moderate probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires a high‑privileged attacker with remote access to the data domain’s management interface to inject OS commands, which can lead to full system compromise.
OpenCVE Enrichment