CVE-2025-43727: High severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an incorrect Implementation of Authentication Algorithm vulnerability in the RestAPI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43727?
CVE-2025-43727 is classified as a critical vulnerability due to its impact on authentication algorithms.
How do I fix CVE-2025-43727?
To fix CVE-2025-43727, update your Dell PowerProtect Data Domain system to the latest version that addresses this vulnerability.
What versions of Dell PowerProtect Data Domain are affected by CVE-2025-43727?
CVE-2025-43727 affects Dell PowerProtect Data Domain versions 7.7.1.0 to 8.1.0.10 and other specified LTS release versions.
What kind of impact can CVE-2025-43727 have on my system?
CVE-2025-43727 can potentially allow unauthorized access due to improper implementation of authentication algorithms.
Are there any workarounds for CVE-2025-43727?
There are no recommended workarounds for CVE-2025-43727; applying the security update is essential for mitigation.