Impact
Dell PowerProtect Data Domain suffers from an improper link resolution before file access, also known as link following. During file access operations the system follows symbolic or relative links without adequate validation, potentially exposing internal files to an attacker. This flaw corresponds to CWE‑59 and, if a high‑privilege attacker has remote access, could lead to information disclosure.
Affected Systems
Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, the LTS2026 release versions 8.6.1.0 through 8.6.1.10, the LTS2025 release versions 8.3.1.0 through 8.3.1.30, and the LTS2024 release versions 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.9, reflecting moderate severity. The EPSS score of <1% indicates a low likelihood that this flaw will be actively exploited. It is not listed in the CISA KEV catalog. Exploitation requires a high‑privilege attacker who already has remote access, after which the improper link resolution can expose internal files and lead to information disclosure.
OpenCVE Enrichment