CVE-2026-53483

dell data_domain_operating_system: unzureichende Authentifizierung

criticalEPSS 0.6%

Affected

  • dell/data_domain_operating_system between 7.7.1.0..7.13.1.80
  • dell/data_domain_operating_system between 7.14.0.0..8.3.1.40
  • dell/data_domain_operating_system between 8.4.0.0..8.6.1.20
  • dell/data_domain_operating_system between 8.7.0.0..8.8.0.0

Description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.

Affected operating systems

  • other

    dell / data_domain_operating_system

Metrics

9.8
Source: nvd-v3
48.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-07 13:16 UTC
CWE-287

Weakness classes (CWE)

  • CWE-287Class

    Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-08 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-53483","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-53483","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…

Linked advisories