CVE-2025-46644: OS Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46644?
CVE-2025-46644 has been designated with a high severity rating due to its potential impact on data integrity.
How do I fix CVE-2025-46644?
To address CVE-2025-46644, you should update Dell PowerProtect Data Domain to the recommended version as specified in the security advisory.
Which versions are affected by CVE-2025-46644?
CVE-2025-46644 affects Dell PowerProtect Data Domain versions from 7.7.1.0 through 8.4.0.0 and several specific LTS versions.
What type of vulnerability is CVE-2025-46644?
CVE-2025-46644 is classified as an Improper Neutralization vulnerability, which may allow an attacker to inject malicious data.
What are the potential risks associated with CVE-2025-46644?
The risks associated with CVE-2025-46644 include unauthorized access to sensitive data and potential data manipulation.