Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDell Data Domain Operating System
OSDell7.10.1.0 – 7.10.1.60 (excl.)7.13.1.0 – 7.13.1.25 (excl.)8.3.0.0 – 8.3.0.15 (excl.)Dell Powerprotect Data Domain
APPDell< 7.10.1.60Dell Powerprotect Dm5500
HWDellall versionsDell Powerprotect Dm5500 Firmware
OSDell5.12 – 5.19.0.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2026-53483CRITICAL9.8PL ✓same product
Obejście uwierzytelniania w Dell PowerProtect Data Domain (Auth Bypass)
CVE-2026-53481CRITICAL9.8PL ✓same product
Path Traversal w Dell PowerProtect Data Domain umożliwia przejęcie systemu
CVE-2025-36594CRITICAL9.8PL ✓same product
Authentication Bypass by Spoofing w Dell PowerProtect Data Domain DD OS
CVE-2026-41122HIGH7.1PL ✓same product
Stored XSS w Dell PowerProtect Data Domain — kradzież sesji
CVE-2026-53482HIGH7.5PL ✓same product
Integer overflow w Dell PowerProtect Data Domain — podatność DoS