Impact
The Dell PowerProtect Data Domain feature releases 7.7.1.0 through 8.6.0.0, 8.7.0.0, LTS2025 8.3.1.0 through 8.3.1.20, and LTS2024 7.13.1.0 through 7.13.1.60 suffer from an OS Command Injection due to improper neutralization of special elements. A high privileged attacker with local access could potentially exploit this flaw to execute arbitrary commands with root privileges.
Affected Systems
The vulnerable versions are Dell PowerProtect Data Domain 7.7.1.0 through 8.7.0.0, LTS2025 releases 8.3.1.0 through 8.3.1.20, and LTS2024 releases 7.13.1.0 through 7.13.1.60. Any appliance running these builds is susceptible until updated to a patched release.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score of 0.00571 shows a very low exploitation probability. The vulnerability requires local, highly privileged access, which further limits its likelihood. The issue is not listed in the CISA KEV catalog. Because the attack needs local control, the risk is confined to environments where administrative credentials or physical access can be compromised, though a successful exploit would grant full system compromise.
OpenCVE Enrichment