Impact
The vulnerability is an improper link resolution before file access (CWE‑59). An attacker with high‑privileged local access can manipulate the resolution process and read files that should be protected, leading to unauthorized access of local data on the appliance.
Affected Systems
Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.6, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, or LTS2024 releases 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score is below 1 % with no listing in CISA’s KEV catalog, meaning public exploitation is unlikely. However, the flaw requires an attacker to have high‑privileged local access to the appliance; available information does not indicate that remote exploitation is feasible or that physical compromise is mandatory.
OpenCVE Enrichment