Executive brief
Dell PowerProtect One is a data protection and disaster recovery solution used by enterprises to safeguard critical systems and workloads. An unauthenticated attacker with network access can bypass the product's security mechanisms by exploiting improper certificate validation, potentially allowing unauthorized access or man-in-the-middle attacks on protected systems.
Technical details
The vulnerability is an improper certificate validation flaw in Dell PowerProtect One versions 20.1.0.0 and below. An unauthenticated attacker with network access can exploit this by presenting invalid or forged certificates, bypassing the product's protection mechanisms. The attack requires no authentication, has high attack complexity, and results in confidentiality compromise. Patches are available through Dell security update DSA-2026-369.
Affected products
- Dell PowerProtect One 20.1.0.0 and below
Timeline
- 2026-08-26: disclosed
- 2026-08-26: advisory: DSA-2026-369 published