Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Published: 2026-07-03
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use of less trusted source (CWE‑348). A remote attacker who can acquire high privileged remote access could supply input that the system incorrectly treats as trusted, permitting the attacker to modify stored information.

Affected Systems

Dell PowerProtect Data Domain appliances in versions 7.7.1.0 through 8.7, the LTS2026 release series 8.6.1.0 through 8.6.1.10, the LTS2025 release series 8.3.1.0 through 8.3.1.30, and the LTS2024 release series 7.13.1.0 through 7.13.1.70 are affected.

Risk and Exploitability

The CVSS score of 2.7 combined with an EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability requires remote authentication with high privileges and the ability to supply malicious data, creating a risk of intentional data tampering.

Generated by OpenCVE AI on July 21, 2026 at 09:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Security Advisory DSA‑2026‑278 update for PowerProtect Data Domain to resolve the use of less trusted source vulnerability.
  • Restrict management interface access to trusted hosts using network segmentation or firewall rules.
  • Enforce role‑based access controls and maintain audit logs to detect unauthorized data modifications.

Generated by OpenCVE AI on July 21, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Use of Less Trusted Source Allows Remote Privileged Attacker to Tamper with Data

Wed, 15 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Use of Less Trusted Source Allows Remote Privileged Attacker to Tamper with Data

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Information Tampering Vulnerability in Dell PowerProtect Data Domain Through Improper Trust of Inputs

Sat, 11 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Information Tampering Vulnerability in Dell PowerProtect Data Domain Through Improper Trust of Inputs

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Information Tampering via Use of Less Trusted Source in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Information Tampering via Use of Less Trusted Source in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Information Tampering Vulnerability in Dell PowerProtect Data Domain due to Use of Less Trusted Source

Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Information Tampering Vulnerability in Dell PowerProtect Data Domain due to Use of Less Trusted Source

Mon, 06 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Data Domain Use of Less Trusted Source Vulnerability Exploitation

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Data Domain Use of Less Trusted Source Vulnerability Exploitation

Sun, 05 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Use of Less Trusted Source Leading to Information Tampering in Dell PowerProtect Data Domain

Sun, 05 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Use of Less Trusted Source Leading to Information Tampering in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Data Domain Vulnerability Allowing Information Tampering via Trusted Source Misuse

Sat, 04 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Data Domain Vulnerability Allowing Information Tampering via Trusted Source Misuse

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-06T14:18:49.663Z

Reserved: 2026-05-14T17:05:39.859Z

Link: CVE-2026-46466

cve-icon Vulnrichment

Updated: 2026-07-06T14:18:46.041Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:00:04Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source