Impact
The vulnerability is an improper link resolution before file access (CWE‑59). The flaw allows a high‑privileged local attacker to manipulate path resolution and read files that should be restricted, potentially exposing sensitive configuration or credential data on the appliance.
Affected Systems
Dell PowerProtect Data Domain appliances running any of the following versions are affected: 7.7.1.0 through 8.6, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score is below 1 % with no listing in CISA’s KEV catalog, meaning public exploitation is unlikely. The likely attack vector is a high‑privileged local attacker who gains direct access to the appliance; remote exploitation or lower‑privilege access is not supported by the available information.
OpenCVE Enrichment