Impact
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, as well as the LTS2025 release versions 8.3.1.0 through 8.3.1.20 and LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain an improper neutralization of special elements in the OS command processing. A high‑privileged attacker who has local access could exploit this flaw to inject arbitrary commands and achieve root‑level execution.
Affected Systems
Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 are impacted.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity vulnerability, and the EPSS score of 0.00571 (< 1%) shows a very low likelihood of exploitation. Because the flaw requires local high‑privileged access, the attack vector is inferred to be local. The vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation to date. Nonetheless, the potential for root‑level command execution warrants prompt attention.
OpenCVE Enrichment