Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authentication flaw, classified as CWE-287, allows an attacker who does not have prior credentials to bypass the Dell PowerProtect Data Domain appliance’s login mechanisms. This flaw can give the attacker full privileged control over the appliance, enabling any action normally restricted to authorized users, effectively resulting in a remote takeover of the system.

Affected Systems

Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, as well as the LTS2026 release series 8.6.1.0 through 8.6.1.10, the LTS2025 release series 8.3.1.0 through 8.3.1.30, and the LTS2024 release series 7.13.1.0 through 7.13.1.70.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical, indicating the potential for full remote privileges. The EPSS score of less than 1% (approximately 0.00625) suggests a very low but non‑zero likelihood of live exploitation in the wild. The vulnerability is not listed in CISA KEV, meaning it has no known current exploits in the public domain. The likely attack vector is an unauthenticated remote attacker sending a crafted request to the appliance’s authentication interface, which then grants elevated privileges.

Generated by OpenCVE AI on July 24, 2026 at 09:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Domain security update provided in Dell Support KB 000481268 for all affected versions.
  • If an immediate patch is not feasible, isolate the appliance from management‑interface traffic until the update is installed.
  • Enable multi‑factor authentication on all management accounts and review authentication logs to detect and deter unauthorized access attempts.

Generated by OpenCVE AI on July 24, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Authentication Enables Remote Takeover of Dell PowerProtect Data Domain

Tue, 21 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Improper Authentication Enables Remote Takeover of Dell PowerProtect Data Domain

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allowing Remote System Control

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allowing Remote System Control

Tue, 14 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper authentication allows full control of Dell PowerProtect Data Domain

Mon, 13 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper authentication allows full control of Dell PowerProtect Data Domain

Sun, 12 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allows Remote Control

Sat, 11 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allows Remote Control

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass on Dell PowerProtect Data Domain

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass on Dell PowerProtect Data Domain

Thu, 09 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Dell PowerProtect Data Domain

Tue, 07 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T03:56:40.966Z

Reserved: 2026-06-09T17:04:35.250Z

Link: CVE-2026-53483

cve-icon Vulnrichment

Updated: 2026-07-07T13:40:22.378Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:30:08Z

Weaknesses