Impact
An incorrect authorization flaw in Dell PowerProtect Data Domain lets a low‑privileged user with network access bypass role checks and obtain unauthorized control over the system. The flaw is identified as CWE‑863, reflecting a weakness in access‑control enforcement. While the official description does not state that sensitive data will be disclosed, any capability to execute privileged operations could enable further data exposure or damage to system integrity.
Affected Systems
The problem affects Dell PowerProtect Data Domain software versions 7.7.1.0 through 8.6, LTS2024 releases 7.13.1.0‑7.13.1.70, LTS2025 releases 8.3.1.0‑8.3.1.30, and LTS2026 releases 8.6.1.0‑8.6.1.10. Any system running any of these releases is potentially exposed.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is less than 1 %, implying a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale active exploits. Based on the description, a likely attack vector is a remote low‑privileged user who can reach the device over the network.
OpenCVE Enrichment