Impact
Dell PowerProtect Data Domain contains an improper limitation of a pathname to a restricted directory, a classic path traversal vulnerability (CWE-22). An unauthenticated attacker with remote access can forge a path that exits the intended filesystem boundaries, potentially accessing arbitrary files or directories on the appliance. The advisory states that successful exploitation may give the attacker complete control of the system, allowing them to read, modify, or delete data and to execute arbitrary commands, thereby breaching confidentiality, integrity, and availability.
Affected Systems
The affected devices are Dell PowerProtect Data Domain appliances. Vulnerable builds include software versions 7.7.1.0 through 8.7, the LTS2026 release series 8.6.1.0 to 8.6.1.10, the LTS2025 release series 8.3.1.0 to 8.3.1.30, and the LTS2024 release series 7.13.1.0 to 7.13.1.70.
Risk and Exploitability
The CVSS score of 9.8 marks the flaw as critical, while the EPSS score of less than 1% indicates a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Because authentication is not required, an attacker can reach the vulnerable functionality over the network and, after manipulating the pathname, gain unauthorized file access or administrative control, effectively compromising the entire appliance.
OpenCVE Enrichment