CVE-2026-73600
Stack Buffer Overflow in Dell PowerProtect Data Manager File-Level Restore Agent
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contains a stack buffer overflow (CWE-121) in its file-level restore agent. Per Dell's advisory, a high-privileged remote attacker could trigger the overflow and achieve information disclosure; the CVSS 3.1 vector (AV:L/AC:L/PR:L) scores the flaw as triggerable by a low-privileged local actor with no user interaction, and rates the impact high across confidentiality, integrity, and availability. An attacker who successfully exploits it could gain access to sensitive data handled by the restore agent. Any organization running PowerProtect Data Manager at version 20.2.0.0 or earlier is affected. There are currently no known public proof-of-concepts, no reports of in-the-wild exploitation, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade PowerProtect Data Manager to a release later than 20.2.0.0, following Dell's security advisory for the fixed version. Because exploitation requires a privileged attacker, limit high-privilege access to the file-level restore agent and restrict restore-agent network exposure to trusted administrators. No public exploit or in-the-wild exploitation is known, but patch promptly and monitor Dell advisories for updated fixed-release information.
| Dell PowerProtect Data Manager | 20.2.0.0 and below |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.