V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2025-29987
CVE
High

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of A…

CVSS
8.8
High
EPSS
0.01
p71
Published
2025-01-01
Updated
2025-01-01
Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

Tags · CWE
CWE-1220
CAPEC-1
CAPEC-180
Affected products
Powerprotect_data_domain < 7.10.1.60Data_domain_operating_system 7.10.1.0–7.10.1.60Data_domain_operating_system 7.13.1.0–7.13.1.25Data_domain_operating_system 8.3.0.0–8.3.0.15
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.006 · p71
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
data_domain_operating_system*Tracked
powerprotect_data_domain*Tracked
powerprotect_dm5500_firmware*Tracked
Source databases
CVE
Related vulnerabilities