Impact
An improper privilege management flaw exists in the Integrated Dell Remote Access Controller (IDRAC) of Dell PowerProtect Data Domain appliances. The flaw allows a local attacker who already possesses high privileges to elevate their privileges and execute delete operations that should be restricted. The vulnerability is categorized as a CWE‑269 (Access Control). The impact is the potential for a local attacker to gain elevated privileges and perform unauthorized deletions, compromising data integrity and availability.
Affected Systems
The vulnerability affects Dell PowerProtect Data Domain appliances running firmware versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the absence of an EPSS score leaves the exact exploitation probability unknown. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread exploitation yet. A local attacker who has high‑privileged access on the appliance could exploit the flaw through the IDRAC interface, elevating privileges to perform unauthorized delete operations. Because the attack requires local high‑privilege access, it is less likely to be leveraged remotely, but within a compromised environment the risk remains significant.
OpenCVE Enrichment