CVE-2025-29987
HIGHDell PowerProtect Data Domain <8.3.0.15 - Privilege Escalation
Title source: llmDescription
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
Scores
CVSS v3
8.8
EPSS
0.0041
EPSS Percentile
61.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-1220
Status
published
Products (3)
dell/data_domain_operating_system
7.10.1.0 - 7.10.1.60
dell/powerprotect_data_domain
< 7.10.1.60
dell/powerprotect_dm5500_firmware
5.12 - 5.19.0.0
Published
Apr 03, 2025
Tracked Since
Feb 18, 2026