Impact
Dell PowerProtect Data Domain appliances are vulnerable to an OS command injection flaw (CWE-78) stemming from improper neutralization of special elements in a command. The vulnerability allows a remote attacker with high‑privileged credentials to execute arbitrary commands with root privileges, effectively bypassing the appliance’s protection mechanisms and granting full control.
Affected Systems
All Dell PowerProtect Data Domain devices running firmware versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 to 8.6.1.10, LTS2025 releases 8.3.1.0 to 8.3.1.30, and LTS2024 releases 7.13.1.0 to 7.13.1.70 remain affected until a vendor‑issued patch is applied.
Risk and Exploitability
The CVSS base score of 7.2 classifies this flaw as high severity. The EPSS score of 1% indicates a low but non‑zero probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the vulnerability is exploitable remotely by an attacker who possesses high‑privileged access to the device. The risk will persist until the appliance is updated to a firmware version that resolves the command‑injection issue.
OpenCVE Enrichment