ZeroHour

CVE-2026-73600

Stack Buffer Overflow in Dell PowerProtect Data Manager File-Level Restore Agent

CVSS 3.1
7.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contains a stack buffer overflow (CWE-121) in its file-level restore agent. Per Dell's advisory, a high-privileged remote attacker could trigger the overflow and achieve information disclosure; the CVSS 3.1 vector (AV:L/AC:L/PR:L) scores the flaw as triggerable by a low-privileged local actor with no user interaction, and rates the impact high across confidentiality, integrity, and availability. An attacker who successfully exploits it could gain access to sensitive data handled by the restore agent. Any organization running PowerProtect Data Manager at version 20.2.0.0 or earlier is affected. There are currently no known public proof-of-concepts, no reports of in-the-wild exploitation, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Upgrade PowerProtect Data Manager to a release later than 20.2.0.0, following Dell's security advisory for the fixed version. Because exploitation requires a privileged attacker, limit high-privilege access to the file-level restore agent and restrict restore-agent network exposure to trusted administrators. No public exploit or in-the-wild exploitation is known, but patch promptly and monitor Dell advisories for updated fixed-release information.

Affected
Dell PowerProtect Data Manager20.2.0.0 and below
Estimated exposure
unknown (enterprise backup-management deployments; no public install-base or internet-exposure scan data available) — No public active-install counts, appliance scan data, or deployment statistics for PowerProtect Data Manager are available in the provided data; as enterprise data-center software it is typically deployed per organization rather than per…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.

Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.