Description
Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation in IDRAC.
Problem types
CWE-269: Improper Privilege Management
Product status
Any version before 8.7.0.1 or later
Any version before 8.3.1.30 or later
Any version before 7.13.1.70 or later
References
www.dell.com/...protect-data-domain-multiple-vulnerabilities