Impact
This CVE reveals an improper limitation of a pathname to a restricted directory on Dell PowerProtect Data Domain appliances, a classic path‑traversal flaw. An attacker with high privileges and remote access can craft file paths that escape the intended directory and overwrite or modify existing files. The resulting confidentiality or integrity compromise depends on the targeted files, but the flaw can affect critical system files and configuration data.
Affected Systems
Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, including LTS2026 release versions 8.6.1.0 to 8.6.1.10, LTS2025 release versions 8.3.1.0 to 8.3.1.30, and LTS2024 release versions 7.13.1.0 to 7.13.1.70 are impacted.
Risk and Exploitability
The CVSS score of 2.7 reflects low overall risk, and the EPSS score of less than 1 % indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. While exploitation requires remote access and elevated privileges, which limits potential spread, any successful attack would enable an attacker to alter essential files on the appliance.
OpenCVE Enrichment