Impact
Dell PowerProtect Data Domain firmware contains an incorrect authorization flaw (CWE‑863) that allows a high‑privileged local attacker to run arbitrary commands on the appliance, resulting in unauthorized command execution.
Affected Systems
Affected system: Dell PowerProtect Data Domain firmware – versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The CVSS score of 4.2 places the vulnerability in the low‑severity range, while the EPSS score of less than 1% indicates a very low likelihood that attackers will exploit it in the wild. The flaw requires local access with high‑privilege rights and is not listed in the CISA KEV catalog, so the overall risk is limited to users who maintain elevated local privileges on the appliance.
OpenCVE Enrichment