CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-36594

CVSS 9.8v3.1pub. 2025-08-04upd. 2025-10-16

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-290 (Authentication Bypass by Spoofing) involves the DD OS system authentication mechanism being bypassed through impersonation of an authorized entity. A remote, unauthenticated attacker can exploit this flaw to create a new account in the system without possessing any prior privileges. This results in complete circumvention of the system's security mechanisms.

Impact

An attacker can create unauthorized accounts in the system, leading to potential customer data disclosure, system integrity violation, and reduced availability.

Mitigation & patch

Apply patches available from the vendor according to references — detailed information about patched versions is available in Dell security bulletin DSA-2025-159 at: https://www.dell.com/support/kbdoc/en-us/000348708/dsa-2025-159-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities

Who is affected

Dell PowerProtect Data Domain with DD OS in the following versions: Feature Release 7.7.1.0–8.3.0.15, LTS2024 7.13.1.0–7.13.1.25, LTS2023 7.10.1.0–7.10.1.60

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Data Domain Operating System

    OS
    Dell
    7.7.1.0 – 7.10.1.70 (excl.)7.13.1.0 – 7.13.1.30 (excl.)8.0.0.0 – 8.3.1.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-53483CRITICAL9.8PL ✓same product

Obejście uwierzytelniania w Dell PowerProtect Data Domain (Auth Bypass)

CVE-2026-53481CRITICAL9.8PL ✓same product

Path Traversal w Dell PowerProtect Data Domain umożliwia przejęcie systemu

CVE-2026-53482HIGH7.5PL ✓same product

Integer overflow w Dell PowerProtect Data Domain — podatność DoS

CVE-2026-41122HIGH7.1PL ✓same product

Stored XSS w Dell PowerProtect Data Domain — kradzież sesji

CVE-2026-56086HIGH8.8PL ✓same product

Nieprawidłowa autoryzacja w Dell PowerProtect Data Domain