Executive brief
Dell PowerProtect Data Domain, a storage solution used for backup and data protection, is affected by a security vulnerability that could allow a user with low-level access to view sensitive information. To exploit this, an attacker must already have local access to the system. While the risk is considered low, it could lead to the unauthorized exposure of internal system data.
Technical details
A 'Use of Uninitialized Resource' vulnerability (CWE-908) exists in Dell PowerProtect Data Domain across multiple versions, including LTS releases. The flaw allows a low-privileged attacker with local access to potentially expose sensitive information by accessing memory or resources that were not properly cleared or initialized. The vulnerability is assigned a CVSS score of 3.3 (Low) because it requires local authenticated access and only impacts confidentiality. Dell has released updates to address this issue in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: advisory
- 2026-07-03: disclosed