Impact
An operating system command injection flaw exists in Dell PowerProtect Data Domain that allows a high privileged attacker who can reach the system remotely to execute arbitrary commands with root privileges. The vulnerability is a classic OS command injection (CWE‑78) that can lead to total system compromise, including modification of stored data, installation of malware, or disruption of services.
Affected Systems
Dell PowerProtect Data Domain products are affected. The vulnerability spans versions 7.7.1.0 through 8.6, the LTS2025 releases 8.3.1.0 through 8.3.1.20, and the LTS2024 releases 7.13.1.0 through 7.13.1.60.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity of remote exploitation. EPSS information is not provided, and the vulnerability is not listed in CISA KEV at this time, suggesting a lower likelihood of widespread exploitation externally. However, because the flaw requires high privilege and remote access, it poses a significant risk if an attacker can gain remote connectivity to the protected domain.
OpenCVE Enrichment