Impact
An improper neutralization of special elements used in an OS command allows an attacker who has high‑privileged local access to inject and execute arbitrary shell commands on Dell PowerProtect Data Domain appliances. The flaw, classified as CWE‑78, enables malicious use of non‑validated input to build and run arbitrary host commands, potentially giving the attacker complete control over the appliance and the data it protects.
Affected Systems
Dell PowerProtect Data Domain appliances running version 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, while an EPSS score of <1% suggests a low probability of exploitation. Not listed in CISA KEV, the vulnerability requires an attacker to already possess high‑privileged local administrative access—such as physical or console access—to the device. Successful exploitation would enable arbitrary command execution, potentially compromising the entire appliance and the data it stores.
OpenCVE Enrichment