Impact
Dell PowerProtect Data Domain appliances are vulnerable to an OS command injection flaw caused by the improper neutralization of special elements used in operating‑system commands. A high‑privileged attacker with remote access can exploit this weakness to execute arbitrary commands, potentially gaining full control over the device and compromising confidentiality, integrity, and availability.
Affected Systems
Affected appliances include Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, the LTS2026 release series 8.6.1.0 through 8.6.1.10, the LTS2025 release series 8.3.1.0 through 8.3.1.30, and the LTS2024 release series 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate‑to‑high severity, and an EPSS score of 1% suggests a low but non‑negligible chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves privileged remote management interfaces that are reachable over the network, requiring the attacker to obtain high‑level administrative credentials to launch the injection.
OpenCVE Enrichment