Impact
An improper privilege management issue in Dell PowerProtect Data Domain appliances allows an attacker who already has local high‑privilege access to elevate privileges and perform unauthorized delete operations. The flaw is classified as CWE‑269 (Access Control). It exists in Feature Release versions 7.7.1.0 through 8.6.0.0 and 8.7.0.0, as well as LTS2025 release versions 8.3.1.0 through 8.3.1.20 and LTS2024 release versions 7.13.1.0 through 7.13.1.60.
Affected Systems
The vulnerability affects Dell PowerProtect Data Domain appliances running firmware versions 7.7.1.0 through 8.6.0.0 and 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity while the EPSS score of <1% shows low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. An attacker with local high‑privilege access could exploit this flaw to elevate privileges and delete protected data. Because the attack requires local high‑privilege conditions, it is unlikely to be leveraged remotely, but within a compromised environment the risk remains significant.
OpenCVE Enrichment