Impact
An externally‑controlled format string vulnerability (CWE‑134) exists in Dell PowerProtect Data Domain firmware. When a high‑privileged attacker sends crafted data that is processed as a format string, the appliance can disclose arbitrary memory contents and, in some cases, crash a process, resulting in both information leakage and denial of service.
Affected Systems
Dell PowerProtect Data Domain appliances running firmware versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70 are vulnerable.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, while the EPSS score of less than 1 % reflects a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a high‑privileged remote attacker, likely through administrative interfaces that accept user‑supplied data. The attack vector is inferred to be remote administration access rather than local or anonymous access.
OpenCVE Enrichment