PT-2026-33428 · Dell · Dell Powerprotect Data Domain

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-23775

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Domain appliances versions 8.0 through 8.5 Dell PowerProtect Data Domain appliances versions 8.3.1.0 through 8.3.1.10
Description An issue exists where sensitive information is inserted into log files. A low privileged attacker with remote access could exploit this to cause credential exposures. This occurs only on systems with retention lock enabled. Authentication attempts using the compromised credentials would require authorization by a high privileged user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2026-23775

Affected Products

Dell Powerprotect Data Domain