cbcvebase.

Dell Powerprotect Data Domain vulnerabilities

57 known vulnerabilities affecting dell/powerprotect_data_domain.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH25MEDIUM26LOW3

Vulnerabilities

Page 3 of 3
CVE-2023-44279P4MEDIUMCVSS 6.7fixed in 6.2.1.110≥ 7.0, < 7.12.0.02023-12-14
CVE-2023-44279 [MEDIUM] CWE-78 CVE-2023-44279: Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit this vulnerability, to bypass security restrictions. Exploitation may lead to a system take over by an attacker
nvd
CVE-2023-44278P4MEDIUMCVSS 6.7fixed in 6.2.1.110≥ 7.0, < 7.12.0.02023-12-14
CVE-2023-44278 [MEDIUM] CWE-22 CVE-2023-44278: Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.
nvd
CVE-2026-46465P4MEDIUMCVSS 5.5fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46465 [MEDIUM] CWE-134 CVE-2026-46465: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially explo
nvd
CVE-2026-46467P4MEDIUMCVSS 5.8fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46467 [MEDIUM] CWE-532 CVE-2026-46467: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially e
nvd
CVE-2026-46464P4MEDIUMCVSS 4.9fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46464 [MEDIUM] CWE-59 CVE-2026-46464: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged attacker with remote access coul
nvd
CVE-2023-44286P4MEDIUMCVSS 6.1fixed in 6.2.1.110≥ 7.0, < 7.12.0.02023-12-14
CVE-2023-44286 [MEDIUM] CWE-79 CVE-2023-44286: Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM environment in the browser. . Exploitation
nvd
CVE-2023-44284P4MEDIUMCVSS 4.3fixed in 6.2.1.110≥ 7.0, < 7.12.0.02023-12-14
CVE-2023-44284 [MEDIUM] CWE-89 CVE-2023-44284: Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
nvd
CVE-2026-41123P4MEDIUMCVSS 4.3fixed in 8.7.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-41123 [MEDIUM] CWE-284 CVE-2026-41123: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this
nvd
CVE-2026-28263P4MEDIUMCVSS 4.8≥ 7.13.1.0, ≤ 7.13.1.50≥ 8.3.1.0, ≤ 8.3.1.20+4 more2026-04-17
CVE-2026-28263 [MEDIUM] CWE-79 CVE-2026-28263: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker with remote access could potentially exploit this vulner
nvd
CVE-2026-41124P4MEDIUMCVSS 4.4fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-41124 [MEDIUM] CWE-22 CVE-2026-41124: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with lo
nvd
CVE-2026-44269P4MEDIUMCVSS 4.4fixed in 8.7.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-44269 [MEDIUM] CWE-59 CVE-2026-44269: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('link following') vulnerability. A high privileged attacker with local access could
nvd
CVE-2026-46468P4MEDIUMCVSS 4.4fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46468 [MEDIUM] CWE-59 CVE-2026-46468: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged attacker with local access could
nvd
CVE-2026-44268P4MEDIUMCVSS 4.4fixed in 8.7.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-44268 [MEDIUM] CWE-732 CVE-2026-44268: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect permission Assignment for critical resource vulnerability. A high privileged attacker with local access could potenti
nvd
CVE-2026-46730P4MEDIUMCVSS 4.2fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46730 [MEDIUM] CWE-863 CVE-2026-46730: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabilit
nvd
CVE-2026-53480P4LOWCVSS 2.7fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-08
CVE-2026-53480 [LOW] CWE-22 CVE-2026-53480: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remot
nvd
CVE-2026-56085P4LOWCVSS 3.3fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-56085 [LOW] CWE-908 CVE-2026-56085: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabil
nvd
CVE-2026-46466P4LOWCVSS 2.7fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46466 [LOW] CWE-348 CVE-2026-46466: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabili
nvd
Dell Powerprotect Data Domain vulnerabilities | cvebase