CVE-2025-29987

EUVD-2025-9648
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
dellCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
dellpowerprotect_data_domain
𝑥
< 7.10.1.60
delldata_domain_operating_system
7.10.1.0 ≤
𝑥
< 7.10.1.60
delldata_domain_operating_system
7.13.1.0 ≤
𝑥
< 7.13.1.25
delldata_domain_operating_system
8.3.0.0 ≤
𝑥
< 8.3.0.15
dellpowerprotect_dm5500_firmware
5.12 ≤
𝑥
< 5.19.0.0
𝑥
= Vulnerable software versions