Impact
An improper authentication flaw, classified as CWE‑287, allows an attacker with no credentials to bypass the PowerProtect Data Domain appliance’s login controls. This vulnerability can grant full privileged access to the system, enabling any operation normally restricted to authorized users and effectively providing remote takeover of the appliance.
Affected Systems
Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical, indicating the potential for full remote control. The EPSS score of less than 1% shows a very low but non‑zero likelihood of live exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits. The attack vector is likely an unauthenticated remote attacker sending a crafted request to the appliance’s authentication interface, which then grants elevated privileges.
OpenCVE Enrichment