CVE-2025-29987: High severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29987?
CVE-2025-29987 is classified as a high-severity vulnerability due to its potential for unauthorized command execution with root privileges.
How do I fix CVE-2025-29987?
To mitigate CVE-2025-29987, upgrade to Dell PowerProtect Data Domain versions 8.3.0.15 or later.
Who is affected by CVE-2025-29987?
CVE-2025-29987 affects authenticated users of Dell PowerProtect Data Domain systems running versions prior to 8.3.0.15.
What type of vulnerability is CVE-2025-29987?
CVE-2025-29987 is an Insufficient Granularity of Access Control vulnerability that allows for arbitrary command execution.
Can CVE-2025-29987 be exploited remotely?
Yes, CVE-2025-29987 can be exploited by authenticated users from a trusted remote client.