CVE-2025-36594: Critical severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36594?
CVE-2025-36594 is classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2025-36594?
To mitigate CVE-2025-36594, upgrade your Dell PowerProtect Data Domain to the latest patched version.
What versions are affected by CVE-2025-36594?
CVE-2025-36594 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.3.0.15 and various LTS versions including 7.10.1.0 to 7.10.1.60.
What impact does CVE-2025-36594 have on security?
CVE-2025-36594 can allow unauthorized users to bypass authentication, leading to potential data breaches.
Is there a workaround for CVE-2025-36594 if I cannot upgrade?
Currently, there are no recommended workarounds for CVE-2025-36594, thus upgrading is the best course of action.