Impact
Dell PowerProtect Data‑of‑uninitialized‑resource vulnerability that allows a local, low‑privileged attacker to read data that has not been properly initialized, exposing potentially sensitive information. The weakness is classified as CWE‑908 and does not provide a path for privilege escalation or denial of service, but it compromises confidentiality within the impacted system.
Affected Systems
Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70 are impacted.
Risk and Exploitability
The CVSS score is 3.3, and the EPSS score is very low (<1 %). The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local low‑privileged access; an attacker who obtains local access can read uninitialized data and gain confidential information.
OpenCVE Enrichment