Impact
The vulnerability is an OS command injection caused by improper neutralization of special command elements (CWE-78). A high-privileged attacker with local access can manipulate input that is passed straight to the operating system, allowing execution of arbitrary commands with root privileges. This could lead to complete compromise of the device, including loss of confidentiality, integrity, and availability of stored data.
Affected Systems
Dell PowerProtect Data Domain devices are affected in all Feature Release versions from 7.7.1.0 up to 8.6.0.0, including version 8.7.0.0, as well as the LTS2025 release series 8.3.1.0 through 8.3.1.20 and the LTS2024 release series 7.13.1.0 through 7.13.1.60. The affected products include the PowerProtect DP Series appliances and the associated Data Domain operating system 8.7.0.0 and prior releases.
Risk and Exploitability
The CVSS score of 6.7 indicates a high overall severity for this vulnerability. The EPSS score is less than 1%, and the issue is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. The likely attack vector is local; a user who gains high privileged access can exploit the command injection to run arbitrary commands as root, potentially compromising the entire system and its stored data. Given the root-level impact, the risk is moderate to high, especially in environments where local administrators may be compromised or during maintenance windows.
OpenCVE Enrichment