Impact
The vulnerability is a stored cross‑site scripting flaw in the web interface of Dell PowerProtect Data Domain. It allows an attacker to inject malicious script content that is saved by the system and executed automatically whenever a legitimate user accesses a page that displays the injected data. Once executed in the victim’s browser, the script can read sensitive information exposed in the page context, hijack session cookies, or trigger client‑side HTTP requests on behalf of the user, thereby enabling information disclosure, session theft, or client‑side request forgery.
Affected Systems
Dell PowerProtect Data Domain systems running firmware versions 7.7.1.0 through 8.7, the LTS2026 release 8.6.1.0 through 8.6.1.10, the LTS2025 release 8.3.1.0 through 8.3.1.30, and the LTS2024 release 7.13.1.0 through 7.13.1.70 are affected. The attackers need only unauthenticated remote access to the web interface; no special configuration changes or privileged accounts are required.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not recorded in the CISA KEV catalog. An unauthenticated attacker who can reach the Data Domain web interface can submit a crafted request containing the malicious script, which the system stores and serves to legitimate users. Upon viewing the affected page, any user’s browser will run the injected code, leading to the potential impacts described above.
OpenCVE Enrichment