CVE-2025-30097: OS Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30097?
CVE-2025-30097 has been rated as a high severity vulnerability due to improper neutralization of special elements.
How do I fix CVE-2025-30097?
To fix CVE-2025-30097, it is recommended to upgrade to the latest version of Dell PowerProtect Data Domain that addresses this vulnerability.
Which versions of Dell PowerProtect Data Domain are affected by CVE-2025-30097?
CVE-2025-30097 affects versions 7.7.1.0 to 8.1.0.10, 7.13.1.0 to 7.13.1.25, and 7.10.1.0 to 7.10.1.50.
What type of vulnerability is CVE-2025-30097?
CVE-2025-30097 is classified as an improper neutralization vulnerability related to input validation.
Is CVE-2025-30097 a local or remote vulnerability?
CVE-2025-30097 is considered a remote vulnerability, allowing attackers to exploit it from outside the local environment.