CVE-2025-43911: OS Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution. Exploitation may allow privilege escalation to root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43911?
CVE-2025-43911 has been classified with a high severity rating due to potential exploitation risks.
How do I fix CVE-2025-43911?
To fix CVE-2025-43911, users should update their Dell PowerProtect Data Domain systems to the specified patched versions released by Dell.
What systems are affected by CVE-2025-43911?
CVE-2025-43911 affects Dell PowerProtect Data Domain systems operating on specific versions of the Data Domain Operating System as indicated in the vulnerability listing.
When was CVE-2025-43911 disclosed?
CVE-2025-43911 was disclosed as part of a security update addressing multiple vulnerabilities in Dell PowerProtect Data Domain.
Can CVE-2025-43911 be exploited remotely?
Yes, CVE-2025-43911 can potentially be exploited remotely, increasing the urgency for remediation.