HIGH✓ PATCH🇬🇧 English

CVE-2025-29987

CVSS 8.8v3.1pub. 2025-04-03upd. 2026-01-22

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Dell Data Domain Operating System

    OS
    Dell
    7.10.1.0 – 7.10.1.60 (bez)7.13.1.0 – 7.13.1.25 (bez)8.3.0.0 – 8.3.0.15 (bez)
  • Dell Powerprotect Data Domain

    APP
    Dell
    < 7.10.1.60
  • Dell Powerprotect Dm5500

    HW
    Dell
    wszystkie wersje
  • Dell Powerprotect Dm5500 Firmware

    OS
    Dell
    5.12 – 5.19.0.0 (bez)
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-53483CRITICAL9.8PL ✓ten sam produkt

Obejście uwierzytelniania w Dell PowerProtect Data Domain (Auth Bypass)

CVE-2026-53481CRITICAL9.8PL ✓ten sam produkt

Path Traversal w Dell PowerProtect Data Domain umożliwia przejęcie systemu

CVE-2025-36594CRITICAL9.8PL ✓ten sam produkt

Authentication Bypass by Spoofing w Dell PowerProtect Data Domain DD OS

CVE-2026-41122HIGH7.1PL ✓ten sam produkt

Stored XSS w Dell PowerProtect Data Domain — kradzież sesji

CVE-2026-53482HIGH7.5PL ✓ten sam produkt

Integer overflow w Dell PowerProtect Data Domain — podatność DoS