Impact
Investigation revealed that Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 suffer from an improper neutralization of argument delimiters in a command, constituting an argument injection (CWE‑88) flaw. A local attacker with high privileges can inject arbitrary arguments to command execution and run commands with root privileges, jeopardizing the confidentiality, integrity, and availability of the appliance.
Affected Systems
Dell PowerProtect Data Domain software versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 are vulnerable.
Risk and Exploitability
The CVSS score is 6.7, indicating moderate severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Exploitation requires local high privileged access, which limits the attack surface. Nevertheless, once local root privileges are achieved, an attacker can execute arbitrary commands, making the impact significant for confidentiality, integrity and availability. Immediate patching is advised.
OpenCVE Enrichment