CVE-2025-29987
EUVD-2025-964803.04.2025, 16:15
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dell | powerprotect_data_domain | 𝑥 < 7.10.1.60 |
| dell | data_domain_operating_system | 7.10.1.0 ≤ 𝑥 < 7.10.1.60 |
| dell | data_domain_operating_system | 7.13.1.0 ≤ 𝑥 < 7.13.1.25 |
| dell | data_domain_operating_system | 8.3.0.0 ≤ 𝑥 < 8.3.0.15 |
| dell | powerprotect_dm5500_firmware | 5.12 ≤ 𝑥 < 5.19.0.0 |
𝑥
= Vulnerable software versions