Impact
Dell PowerProtect Data Domain firmware contains an incorrect permission assignment for a critical resource, as identified by CWE-732. An attacker with high‑privileged local access could use this flaw to access or modify data or settings that should not be freely available, allowing unauthorized control over protected resources.
Affected Systems
Affected are Dell PowerProtect Data Domain firmware versions 7.7.1.0 through 8.6, LTS2026 releases 8.6.1.0 to 8.6.1.10, LTS2025 releases 8.3.1.0 to 8.3.1.30, and LTS2024 releases 7.13.1.0 to 7.13.1.70.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate overall risk, while the EPSS score of < 1% reflects a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires local high‑privileged access, and it does not provide remote code execution or full system compromise.
OpenCVE Enrichment