Do You Use Dell PowerProtect? Critical Vulnerabilities Could Allow Attackers to Completely Compromise Your System Remotely!

Imported from official source

Announcement

Dell Technologies has released urgent security updates to address several critical vulnerabilities discovered in its PowerProtect Data Domain products. According to security experts, if successfully exploited, these vulnerabilities could allow attackers to gain complete control of affected systems remotely and without any authentication.

PowerProtect Data Domain systems are widely used to store backup data, disaster recovery information, and other mission-critical organizational assets. As a result, vulnerabilities affecting these platforms are far more than ordinary software flaws—they represent a significant threat to an organization’s overall cybersecurity posture.

The identified vulnerabilities affect the following Dell products:

  • Dell PowerProtect Data Domain Appliances
  • Dell PowerProtect Data Domain Virtual Edition (DDVE)
  • These solutions are extensively deployed across large enterprises, government organizations, and data centers to safeguard backup data and ensure business continuity.

    Dell’s security advisory highlights two vulnerabilities as particularly severe.

    This vulnerability has been assigned a CVSS score of 9.8 and is classified as an Improper Authentication flaw.

    Due to this weakness, a remote attacker can gain unauthorized access to a vulnerable system without providing valid credentials.

    If successfully exploited, an attacker could:

  • Access, manipulate, or delete stored data.
  • CVE-2026-53481 — Path Traversal Vulnerability

    The second critical issue, CVE-2026-53481, has also received a CVSS score of 9.8.

    This vulnerability is classified as a Path Traversal flaw, allowing an attacker to bypass directory restrictions and access files and folders outside the intended directories.

  • Unauthorized access to system resources;
  • Full compromise of the affected platform.
  • Both vulnerabilities are remotely exploitable over the network, require no complex attack techniques, and do not require any user interaction, making them particularly dangerous in real-world environments.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/do-you-use-dell-powerprotect-critical-vulnerabilities-could-allow-attackers-to-completely-compromise-your-system-remotely/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39198

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.