Impact
Dell PowerProtect Data Domain has a flaw that causes sensitive information to be written into audit logs, a CWE‑532 vulnerability. The description does not mention any impact on data integrity or system availability, so the issue is limited to potential exposure of credentials, configuration details, or other private data stored in the logs.
Affected Systems
Affected releases include Dell PowerProtect Data Domain 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70. Any appliance running these versions in a local environment is vulnerable.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate risk level, and the EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged attacker with local access to trigger the logging mechanism, after which the attacker can read sensitive data from the log files, threatening confidentiality. The likely attack vector is local, and the direct impact is information disclosure.
OpenCVE Enrichment