TROYANOSYVIRUS
Back to CVEs

CVE-2025-29987

HIGH
8.8

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published4/3/2025
Last Modified1/22/2026
Sourcenvd
Honeypot Sightings0

Affected Products

dell:data_domain_operating_systemdell:powerprotect_data_domaindell:powerprotect_dm5500dell:powerprotect_dm5500_firmware

Weaknesses (CWE)

CWE-1220

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.