Dell PowerProtect Data Domain Improper Authentication Vulnerability Allowing Unauthorized Access

Vulnerability

A vulnerability has been identified in Dell PowerProtect Data Domain appliances running Data Domain Operating System (DD OS) Feature Release versions 8.4 through 8.5. This vulnerability arises from improper authentication, potentially allowing a high-privileged attacker with remote access to exploit it and gain unauthorized access to the system.

Impact

Exploitation of this vulnerability could lead to unauthorized access on the affected system.

Remediation

Users can upgrade to Dell PowerProtect Data Domain DD OS version 8.6.1.10, 8.7.0.0 or later. For instructions on how to upgrade, see the Dell PowerProtect Data Domain Upgrade Guide. After upgrading, some security scanners may still report false positive findings. For more details, refer to the Dell PowerProtect Data Domain False Positive Security Vulnerabilities Knowledge Base articles.

Added: Apr 17, 2026, 12:22 PM
Updated: Apr 17, 2026, 12:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
6.3
remediation
7.7
relevance
6.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.