Impact
The vulnerability is an OS command injection, classified as CWE‑78. An attacker with high‑priv crafted input that is executed as an operating system command, allowing arbitrary code execution with the privileges of the affected process. This threat can compromise confidentiality control over the host.
Affected Systems
The affected product is Dell PowerProtect Data Domain. Versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 are impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and the EPSS score of 1% shows a very low yet nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no publicly disclosed exploits at this time. Exploitation requires remote high‑privilege access, but once achieved it enables arbitrary OS command execution and full system compromise.
OpenCVE Enrichment