CVE-2025-43907: Path Traversal
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain a Path Traversal: '.../...//' vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43907?
CVE-2025-43907 has been rated as a high severity vulnerability due to its path traversal exploit.
How do I fix CVE-2025-43907?
To mitigate CVE-2025-43907, update your Dell PowerProtect Data Domain to the latest version provided by Dell.
What systems are affected by CVE-2025-43907?
CVE-2025-43907 affects Dell PowerProtect Data Domain systems running specific versions of DD OS, ranging from 7.7.1.0 to 8.3.0.15.
What kind of vulnerability is CVE-2025-43907?
CVE-2025-43907 is classified as a path traversal vulnerability.
Are there any workarounds for CVE-2025-43907?
Currently, the primary recommended action for CVE-2025-43907 is to apply the latest patches provided by Dell.