Impact
An OS command injection flaw arises from classified as CWE‑78. The vulnerability allows a high‑privileged attacker with local access to inject and execute arbitrary operating‑system commands on Dell PowerProtect Data Domain appliances. Such exploitation can compromise system integrity, enable unauthorized data modification, and potentially lead to further escalation or data disclosure.
Affected Systems
Dell PowerProtect Data Domain appliances running firmware versions 7.7.1.0 through 8.6, LTS2026 series 8.6.1.0 to 8.6.1.10, LTS2025 series 8.3.1.0 to 8.3.1.30, and LTS2024 series 7.13.1.0 to 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 6.7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread attacks. Exploitation requires high‑privileged local access; thus limiting such access mitigates the threat.
OpenCVE Enrichment