CVE-2025-36569: OS Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36569?
CVE-2025-36569 has been assessed with a critical severity rating due to the risk it poses to affected systems.
How do I fix CVE-2025-36569?
To fix CVE-2025-36569, update your Dell PowerProtect Data Domain software to the latest patched version.
What versions are affected by CVE-2025-36569?
CVE-2025-36569 affects Dell PowerProtect Data Domain versions from 7.7.1.0 to 8.1.0.10, 7.13.1.0 to 7.13.1.25, and 7.10.1.0 to 7.10.1.50.
What types of vulnerabilities does CVE-2025-36569 include?
CVE-2025-36569 includes an improper neutralization of special elements used in an output, leading to potential security risks.
Is there a security update available for CVE-2025-36569?
Yes, Dell has released a security update to address CVE-2025-36569 which should be applied immediately.