Impact
Improper access control within the RBAC system of Dell PowerProtect Data Domain allows a low‐privileged attacker with remote access to modify stored information, potentially leading to data integrity violations. The weakness is identified as CWE‑284.
Affected Systems
Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.6, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, whereas the EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability requires remote access to the appliance's management interface and exploitation of the RBAC flaw, enabling unauthorized modifications.
OpenCVE Enrichment