Description
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-09-03
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack buffer overflow exists in the file‑level restore agent component of Dell PowerProtect Data Manager. This flaw can allow a high‑privileged remote attacker to read sensitive data from the system. The weakness is a classic memory corruption issue (overflow) that may expose confidential information without affecting the integrity of the data. The attack does not provide a direct remote code execution path, but the leakage of internal data could be used in further attacks or for reconnaissance.

Affected Systems

Dell PowerProtect Data Manager versions 20.2.0.0 and any earlier releases are affected. The vulnerability lies within the file‑level restore agent service that performs restore operations for stored data, and it has been identified specifically for these product versions.

Risk and Exploitability

The CVSS score of 7.8 places the flaw in the high‑severity range, indicating significant risk when the conditions are met. Although the EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests no current widespread exploitation. The vulnerability requires remote access and high privileges to achieve exploitation, so the likelihood of successful attacks depends on the attacker’s privilege level. Nevertheless, if an attacker gains the necessary access, they could gain confidential data from the protected storage system.

Generated by OpenCVE AI on September 3, 2026 at 13:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Manager security update provided in DSA 2026‑368, which restores the file‑level restore agent to a safe implementation.
  • After applying the update, monitor system logs for anomalous restore activity and verify that the buffer size checks are enforced in the agent code.
  • Restrict the exposure of the file‑level restore service by disabling remote restore capability on untrusted networks or implementing network access control to allow only trusted hosts.

Generated by OpenCVE AI on September 3, 2026 at 13:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in PowerProtect Data Manager's File‑Level Restore Agent Enables Information Disclosure

Thu, 03 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Thu, 03 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-03T13:20:43.751Z

Reserved: 2026-08-13T11:04:26.935Z

Link: CVE-2026-73600

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T13:06:03.427

Modified: 2026-09-03T13:06:03.427

Link: CVE-2026-73600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:15:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow