Impact
Dell PowerProtect Data Domain has a path traversal vulnerability (CWE-22). A high-privileged local attacker may read files outside the designated restricted directory, potentially exposing sensitive information. The vulnerable code does not enforce proper path limiting, allowing traversal to parent directories that are not intended to be accessed.
Affected Systems
Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The EPSS score is <1%, indicating a very low likelihood of exploitation. The CVSS score of 2.3 classifies this as low severity and it is not listed in the CISA KEV catalog. Exploitation requires local access with high privileges; a remote attacker would first need to compromise a user with sufficient rights on the appliance.
OpenCVE Enrichment