Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow or wraparound flaw exists in Dell PowerProtect Data Domain. The vulnerability allows an unauthenticated remote attacker to supply numeric values that exceed the bounds of an integer data type, causing the software to behave unpredictably. Triggering the flaw can lead to a crash or loss of responsiveness, resulting in a denial of service for users.

Affected Systems

Dell PowerProtect Data Domain is vulnerable. The flaw affects versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70.

Risk and Exploitability

The vulnerability can be exploited by an unauthenticated attacker that can reach the system remotely. The EPSS score is listed as <1%, indicating a low projected likelihood of exploitation, but the CVSS score of 7.5 signals high severity. The flaw is not included in the CISA KEV catalog. Given the high impact and potential for service interruption, timely mitigation is recommended.

Generated by OpenCVE AI on July 26, 2026 at 18:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update for PowerProtect Data Domain to all affected versions as distributed by Dell
  • Restrict remote access to the PowerProtect Data Domain management interface by configuring firewalls or ACLs to allow only trusted IP ranges
  • Enable and monitor detailed logging for administrative and operational activities to detect abnormal behavior that could indicate exploitation

Generated by OpenCVE AI on July 26, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Dell PowerProtect Data Domain Leading to Denial of Service

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote Integer Overflow Leading to Denial of Service in Dell PowerProtect Data Domain

Tue, 21 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Integer Overflow Leading to Denial of Service in Dell PowerProtect Data Domain

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Vulnerability in Dell PowerProtect Data Domain Allowing Remote Denial of Service

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow Vulnerability in Dell PowerProtect Data Domain Allowing Remote Denial of Service

Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Dell PowerProtect Data Domain Enables Remote Denial of Service

Mon, 13 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Dell PowerProtect Data Domain Enables Remote Denial of Service

Sat, 11 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow Causing Denial of Service in Dell PowerProtect Data Domain

Fri, 10 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Causing Denial of Service in Dell PowerProtect Data Domain

Fri, 10 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Vulnerability in Dell PowerProtect Data Domain Leading to Denial of Service

Thu, 09 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Vulnerability in Dell PowerProtect Data Domain Leading to Denial of Service

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-09T13:31:31.768Z

Reserved: 2026-06-09T17:04:35.250Z

Link: CVE-2026-53482

cve-icon Vulnrichment

Updated: 2026-07-09T13:31:25.751Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:15:17Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound