Impact
Dell PowerProtect Data Domain firmware contains an authorization flaw (CWE‑863) that lets a high‑privileged local attacker run arbitrary commands on the appliance, enabling unauthorized command execution.
Affected Systems
Affected system: Dell PowerProtect Data Domain firmware – versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The CVSS score of 4.2 places the vulnerability in the low‑severity range and the EPSS score of <1% indicates a very low probability of exploitation. The flaw requires local access with high‑privilege rights and is not listed in the CISA KEV catalog. Consequently, the risk is confined to users who maintain elevated local privileges on the appliance.
OpenCVE Enrichment