Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A vulnerability in this system allows a remote attacker to trigger a crash or system shutdown without needing any login credentials. This could lead to a significant disruption of data backup and recovery operations, potentially impacting business continuity.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in Dell PowerProtect Data Domain across multiple version branches. The flaw can be triggered by an unauthenticated attacker with network access to the system. Successful exploitation allows the attacker to cause a denial of service (DoS) condition, impacting the availability of the storage appliance. Affected versions include 7.7.1.0 through 8.7, as well as specific LTS releases (2024, 2025, and 2026). Dell has released security updates to address this issue in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10, 8.3.1.0 through 8.3.1.30, 7.13.1.0 through 7.13.1.70
Timeline
- 2026-07-08: disclosed: Initial advisory published by Dell and NVD