CVE-2026-24506
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: security_alert@emc.com (Secondary)
Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.14.0.0 to 8.3.1.30 | |
| Before 2.7.9 |
References (1)
Source: security_alert@emc.com
Vendor Advisory
Timeline
No history available yet.