CVE-2023-44278: Dell Apex Protection Storage

Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A local high privileged attacker could potentially exploit this vulnerability, to gain unauthorized read and write access to the OS files stored on the server filesystem, with the privileges of the running application.

Affected products

  • Dell Apex Protection Storage: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.10.1.15 (fixed in 7.10.1.15)
  • Dell Emc Data Domain OS: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.12.0.0 (fixed in 7.12.0.0); from 7.7, before 7.7.5.25 (fixed in 7.7.5.25); from 7.10, before 7.10.1.15 (fixed in 7.10.1.15)
  • Dell Powerprotect Data Domain: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.12.0.0 (fixed in 7.12.0.0)
  • Dell Powerprotect Data Domain Management Center: before 6.2.1.110 (fixed in 6.2.1.110); from 7.0, before 7.13.0.10 (fixed in 7.13.0.10); from 7.7, before 7.7.5.25 (fixed in 7.7.5.25); from 7.10, before 7.10.1.15 (fixed in 7.10.1.15)
  • Dell Powerprotect Data Protection: before 2.7.6 (fixed in 2.7.6)

Published 2023-12-14. Last modified 2026-06-17.