Impact
The vulnerability is an improper neutralization of special elements used in an OS command, classified as CWE‑78. It allows a high‑privileged attacker with local access to inject and run arbitrary commands on Dell PowerProtect Data Domain appliances, potentially compromising system integrity and data confidentiality.
Affected Systems
Dell PowerProtect Data Domain appliances with versions 7.7.1.0 through 8.6, LTS2026 series 8.6.1.0 through 8.6.1.10, LTS2025 series 8.3.1.0 through 8.3.1.30, and LTS2024 series 7.13.1.0 through 7.13.1.70 are affected.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog, implying no currently widespread exploits. However, the requirement for high‑ arbitrary commands, potentially leading to full system compromise or data exfiltration.
OpenCVE Enrichment