Impact
The vulnerability is an OS command injection flaw (CWE‑78) that allows a high‑privileged attacker who can remotely access the appliance to run arbitrary system commands. It arises from user input being incorporated directly into OS commands, enabling the attacker to execute any code with the privileges of the vulnerable process.
Affected Systems
Dell PowerProtect Data Domain appliances running software versions 7.7.1.0 through 8.7, the LTS2026 release versions 8.6.1.0 through 8.6.1.10, the LTS2025 release versions 8.3.1.0 through 8.3.1.30, and the LTS2024 release versions 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and an EPSS score of 1% shows a low but non‑negligible likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires remote high‑privilege access; once achieved, the attacker can execute commands with the privileges of the vulnerable process, potentially enabling full compromise of the appliance.
OpenCVE Enrichment