Back to CVE List

CVE-2026-35154

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.3 / 10
Vector String
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Vulnerability Description

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation in IDRAC.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-269
Source
NVD
Vendor
Dell
Product
PowerProtect Data Domain appliances

External References

Discussion (0)

Add Comment

No comments yet. Be the first!