CVE-2025-29987

HIGH

Dell PowerProtect Data Domain <8.3.0.15 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

Scores

CVSS v3 8.8
EPSS 0.0041
EPSS Percentile 61.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1220
Status published
Products (3)
dell/data_domain_operating_system 7.10.1.0 - 7.10.1.60
dell/powerprotect_data_domain < 7.10.1.60
dell/powerprotect_dm5500_firmware 5.12 - 5.19.0.0
Published Apr 03, 2025
Tracked Since Feb 18, 2026