Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-07-03
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use of uninitialized resources that allows an attacker with low privileged local access to potentially reveal sensitive information. This weakness is classified under CWE‑908 and can lead to unauthorized data disclosure within the affected Dell PowerProtect Data Domain system.

Affected Systems

Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release 8.6.1.0 through 8.6.1.10, LTS2025 release 8.3.1.0 through 8.3.1.30, and LTS2024 release 7.13.1.0 through 7.13.1.70 are impacted.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity, and the EPSS score is not available. The vulnerability is listed in no KEV catalog. The likely exploitation path requires local, low privileged access, making it less exploitable from a remote perspective. Nonetheless, if an attacker gains local access they could read uninitialized data leading to information disclosure.

Generated by OpenCVE AI on July 3, 2026 at 20:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell DSA‑2026‑278 security update for PowerProtect Data Domain
  • Limit local user permissions and adhere to the principle of least privilege to reduce the risk of local privilege escalation
  • Restrict or remove unnecessary local user accounts that have low‑privileged access to the system

Generated by OpenCVE AI on July 3, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use of Uninitialized Resource Vulnerability Enabling Potential Information Disclosure in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-908
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-03T12:46:42.895Z

Reserved: 2026-06-18T17:04:56.015Z

Link: CVE-2026-56085

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-03T20:45:16Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource