CVE-2025-43934: Path Traversal
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43934?
CVE-2025-43934 is classified as a high-severity vulnerability affecting Dell PowerProtect Data Domain systems.
How do I fix CVE-2025-43934?
To remediate CVE-2025-43934, upgrade your Dell PowerProtect Data Domain system to a fixed version as specified in the security update from Dell.
Which versions of Dell PowerProtect Data Domain are affected by CVE-2025-43934?
CVE-2025-43934 affects Dell PowerProtect Data Domain versions from 7.7.1.0 to 8.3.0.15, along with specific LTS versions indicated.
What type of vulnerability is CVE-2025-43934?
CVE-2025-43934 is categorized as an Improper Limitation on a Path Parameter vulnerability.
Is there a workaround for CVE-2025-43934 before applying a fix?
There is currently no documented workaround for CVE-2025-43934, and it is advised to apply the security update as soon as possible.