Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDell Data Domain Operating System
OSDell7.10.1.0 – 7.10.1.60 (bez)7.13.1.0 – 7.13.1.25 (bez)8.3.0.0 – 8.3.0.15 (bez)Dell Powerprotect Data Domain
APPDell< 7.10.1.60Dell Powerprotect Dm5500
HWDellwszystkie wersjeDell Powerprotect Dm5500 Firmware
OSDell5.12 – 5.19.0.0 (bez)
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Powiązane podatności
CVE-2026-53483CRITICAL9.8PL ✓ten sam produkt
Obejście uwierzytelniania w Dell PowerProtect Data Domain (Auth Bypass)
CVE-2026-53481CRITICAL9.8PL ✓ten sam produkt
Path Traversal w Dell PowerProtect Data Domain umożliwia przejęcie systemu
CVE-2025-36594CRITICAL9.8PL ✓ten sam produkt
Authentication Bypass by Spoofing w Dell PowerProtect Data Domain DD OS
CVE-2026-41122HIGH7.1PL ✓ten sam produkt
Stored XSS w Dell PowerProtect Data Domain — kradzież sesji
CVE-2026-53482HIGH7.5PL ✓ten sam produkt
Integer overflow w Dell PowerProtect Data Domain — podatność DoS