Impact
Dell PowerProtect Data Domain appliances suffer from an improper link resolution before file access flaw (CWE-59) that can allow a local user with administrative privileges to read files that should otherwise be inaccessible, potentially exposing sensitive configuration or data.
Affected Systems
PowerProtect Domain appliances running versions 7.7.1.0 through 8.7, the LTS2026 release series 8.6.1.0 through 8.6.1.10, the LTS2025 release series 8.3.1.0 through 8.3.1.30, and the LTS2024 release series 7.13.1.0 through 7.13.1.70 are impacted.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, but the EPSS score of less than 1% suggests the likelihood of exploitation is very low as of the current data and the vulnerability is not listed in the CISA KEV catalog. Consequently, the risk is primarily confined to environments where local administrative privileges are available; applying vendor patches or restricting such access will effectively reduce the threat.
OpenCVE Enrichment