Impact
An integer overflow or wraparound flaw exists in Dell PowerProtect Data Domain. The vulnerability allows an unauthenticated remote attacker to supply numeric values that exceed the bounds of an integer data type, causing the software to behave unpredictably. Triggering the flaw can lead to a crash or loss of responsiveness, resulting in a denial of service for users.
Affected Systems
Dell PowerProtect Data Domain is vulnerable. The flaw affects versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The vulnerability can be exploited by an unauthenticated attacker that can reach the system remotely. The EPSS score is listed as <1%, indicating a low projected likelihood of exploitation, but the CVSS score of 7.5 signals high severity. The flaw is not included in the CISA KEV catalog. Given the high impact and potential for service interruption, timely mitigation is recommended.
OpenCVE Enrichment