CVE-2025-43905: Medium severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43905?
CVE-2025-43905 is rated as a high severity vulnerability that can lead to unauthorized access or system compromise.
How do I fix CVE-2025-43905?
To fix CVE-2025-43905, update your Dell PowerProtect Data Domain system to the latest available version as specified in the vendor's security advisory.
What are the affected versions for CVE-2025-43905?
CVE-2025-43905 affects Dell PowerProtect Data Domain versions 7.7.1.0 to 8.3.0.15, 7.13.1.0 to 7.13.1.30, and 7.10.1.0 to 7.10.1.60.
What products are impacted by CVE-2025-43905?
CVE-2025-43905 impacts the Dell PowerProtect Data Domain with various versions of the Data Domain Operating System.
Is CVE-2025-43905 being actively exploited?
Currently, there are no public reports indicating that CVE-2025-43905 is being actively exploited in the wild.