CVE-2025-43890: OS Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution. Exploitation may allow privilege escalation to root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43890?
CVE-2025-43890 has a high severity rating due to an improper neutralization issue that can lead to security vulnerabilities.
How do I fix CVE-2025-43890?
To fix CVE-2025-43890, you should upgrade to the latest version of Dell PowerProtect Data Domain software as recommended by Dell.
What versions of Dell PowerProtect Data Domain are affected by CVE-2025-43890?
CVE-2025-43890 affects Dell PowerProtect Data Domain with DD OS versions from 7.7.1.0 to 8.3.0.15, as well as specific LTS2025, LTS2024, and LTS2023 release versions.
Is CVE-2025-43890 being actively exploited?
There is no current evidence indicating that CVE-2025-43890 is being actively exploited, but organizations should take precautions by patching the vulnerability.
What are the potential impacts of CVE-2025-43890?
Exploitation of CVE-2025-43890 could lead to unauthorized access or modification of sensitive data within the affected Dell systems.