Impact
Improper access control within the RBAC system of Dell PowerProtect Data Domain allows a low‑privileged attacker with remote access to modify stored information, potentially leading to data integrity violations. The weakness, identified as CWE‑284, enables an attacker to alter or delete records or configurations without proper authorization, thereby compromising the integrity of the data domain. This vulnerability is a form of privilege escalation that can be leveraged to tamper with data or system settings without the need for elevated credentials.
Affected Systems
Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.6, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 are impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of <1% reflects a very low likelihood of exploitation. The vulnerability requires remote access and a low‑privileged account, making it unlikely to be targeted in the broadest sense but still a concern for environments where such accounts exist.
OpenCVE Enrichment