Impact
Dell PowerProtect Data Domain implementations have a flaw that writes sensitive information into audit log files. The weakness falls under CWE‑532, which involves sensitive data exposure through logs, and allows a local, low‑privileged user to obtain confidential configuration or operational data the system records, thereby compromising confidentiality even though the system remains operational.
Affected Systems
The vulnerability affects Dell PowerProtect Data Domain releases 7.7.1.0 through 8.7, LTS2026 version 8.6.1.0 through 8.6.1.10, LTS2025 8.3.1.0 through 8.3.1.30, and LTS2024 7.13.1.0 through 7.13.1.70. Any appliance running any of those versions in a local environment is susceptible.
Risk and Exploitability
The CVSS score of 5.8 reflects a moderate risk level, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker with local, low‑privileged access to trigger the logging mechanism; once the log is written, the attacker can read it to obtain sensitive data. The likely attack vector is local, with the impact being the disclosure of confidential information.
OpenCVE Enrichment