Impact
Dell PowerProtect Data Domain appliances suffer from an improper link resolution before file access flaw (CWE-59) that can allow a local user with administrative privileges to read files that should otherwise be inaccessible, potentially exposing sensitive configuration or data.
Affected Systems
PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, LTS2026 release 8.6.1.0 through 8.6.1.10, LTS2025 release 8.3.1.0 through 8.3.1.30, and LTS2024 release 7.13.1.0 through 7.13.1.70 are impacted.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, but the EPSS score of less than 1% suggests the likelihood of exploitation is very low as of the current data. The vulnerability requires local high‑privileged access and is not listed in the CISA KEV catalog. Consequently, the risk is primarily confined to environments where local administrative privileges are available; applying vendor patches or restricting such access will effectively reduce the threat.
OpenCVE Enrichment