Impact
Dell PowerProtect Data Domain contains an externally controlled format string vulnerability (CWE‑134). A high‑privileged attacker who can reach the appliance remotely can send crafted input that is processed in a way that allows the attacker to read sensitive information from memory and, in some cases, cause the application to crash. The vulnerability allows the attacker to compromise confidentiality and availability of the data domain services.
Affected Systems
Dell PowerProtect Data Domain appliances running firmware versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is less than 1 %, and the vulnerability is not listed in CISA KEV. Exploitation requires a high‑privileged remote attacker; the issue is unlikely to be triggered by anonymous or limited‑access users.
OpenCVE Enrichment