CVE-2026-46465
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
- EPSS probability
- 0.41%
- CWE
- CWE-134
- Published
- 2026-07-03
- Last modified
- 2026-07-06
Affected products
- Dell PowerProtect Data Domain
Weakness type
Related vulnerabilities
- CVE-2026-69395 — Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability
- CVE-2026-16821 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-81574 — Format String Vulnerability in Logger
- CVE-2026-63073 — Untrusted Sender DN Used as Format String in CMP Response Validation
- CVE-2026-17136 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-68553 — Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command
- CVE-2026-15961 — Power System Information Disclosure
- CVE-2026-12004 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access