CVE-2025-43889: Path Traversal
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release Versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43889?
CVE-2025-43889 is categorized as a medium severity vulnerability affecting Dell PowerProtect Data Domain.
How do I fix CVE-2025-43889?
To fix CVE-2025-43889, upgrade to the latest patch version of Dell PowerProtect Data Domain that addresses this vulnerability.
What is the nature of the vulnerability CVE-2025-43889?
CVE-2025-43889 involves an improper limitation of a pathname to a restricted directory, which may allow unauthorized access.
Which versions of Dell PowerProtect Data Domain are affected by CVE-2025-43889?
CVE-2025-43889 affects versions 7.7.1.0 through 8.4, 7.13.1.0 through 7.13.1.30, and 7.10.1.0 through 7.10.1.60 of Dell PowerProtect Data Domain.
Is there a workaround for CVE-2025-43889?
There is currently no known workaround for CVE-2025-43889; applying the provided security updates is essential.