Impact
An improper neutralization of special elements used in an OS command (CWE-78) allows a high‑privileged attacker with local access to inject arbitrary shell commands into Dell PowerProtect Data Domain. This flaw can lead to the execution of unintended commands, potentially giving the attacker full control over the appliance and the data it stores.
Affected Systems
Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while an EPSS score of <1% points to a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires high‑privileged local administrative access, meaning the attacker must already have physical or privileged console access to the device. If successfully exploited, arbitrary command execution can compromise the entire system and its resident data.
OpenCVE Enrichment