Impact
An improper authentication flaw, classified as CWE-287, allows an attacker who does not have prior credentials to bypass the Dell PowerProtect Data Domain appliance’s login mechanisms. This flaw can give the attacker full privileged control over the appliance, enabling any action normally restricted to authorized users, effectively resulting in a remote takeover of the system.
Affected Systems
Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, as well as the LTS2026 release series 8.6.1.0 through 8.6.1.10, the LTS2025 release series 8.3.1.0 through 8.3.1.30, and the LTS2024 release series 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical, indicating the potential for full remote privileges. The EPSS score of less than 1% (approximately 0.00625) suggests a very low but non‑zero likelihood of live exploitation in the wild. The vulnerability is not listed in CISA KEV, meaning it has no known current exploits in the public domain. The likely attack vector is an unauthenticated remote attacker sending a crafted request to the appliance’s authentication interface, which then grants elevated privileges.
OpenCVE Enrichment