CVE-2026-23853
Weak Credentials Vulnerability in Dell PowerProtect Data Domain
Publication date: 2026-04-17
Last updated on: 2026-04-17
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | powerprotect_data_domain | From 7.7.1.0 (inc) to 8.5 (inc) |
| dell | powerprotect_data_domain | From 8.3.1.0 (inc) to 8.3.1.20 (inc) |
| dell | powerprotect_data_domain | From 7.13.1.0 (inc) to 7.13.1.50 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1391 | The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions ranging from 7.7.1.0 through 8.5, including certain LTS2025 and LTS2024 release versions. It involves the use of weak credentials that can be exploited by an unauthenticated attacker who has local access to the system. Exploiting this weakness could allow the attacker to gain unauthorized access to the system.
How can this vulnerability impact me? :
The impact of this vulnerability is significant because an unauthenticated attacker with local access could exploit weak credentials to gain unauthorized access. This unauthorized access could lead to a complete compromise of confidentiality, integrity, and availability of the affected system, as indicated by the high CVSS score (8.4) with high impact on confidentiality, integrity, and availability.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows an unauthenticated attacker with local access to potentially gain unauthorized access to the system by exploiting weak credentials.
Such unauthorized access could lead to compromise of sensitive data, which may impact compliance with data protection standards and regulations such as GDPR and HIPAA that require strict access controls and protection of personal and health information.