Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to credential exposures. Authentication attempts as the compromised user would need to be authorized by a high privileged DD user. This vulnerability only affects systems with retention lock enabled.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Sensitive Data Leak via Log Injection in Dell PowerProtect Data Domain | |
| Metrics |
ssvc
|
Fri, 17 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to credential exposures. Authentication attempts as the compromised user would need to be authorized by a high privileged DD user. This vulnerability only affects systems with retention lock enabled. | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-04-17T11:01:10.107Z
Reserved: 2026-01-16T06:05:50.872Z
Link: CVE-2026-23775
Updated: 2026-04-17T11:01:05.518Z
Status : Received
Published: 2026-04-17T09:16:05.153
Modified: 2026-04-17T09:16:05.153
Link: CVE-2026-23775
No data.
OpenCVE Enrichment
Updated: 2026-04-17T11:00:13Z