CVE-2025-46676: Infoleak
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46676?
CVE-2025-46676 has been classified as a high severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2025-46676?
To resolve CVE-2025-46676, update Dell PowerProtect Data Domain to the latest versions beyond 8.4.0.0, 7.13.1.40, or 7.10.1.70.
What are the affected versions for CVE-2025-46676?
CVE-2025-46676 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.4.0.0, and specific LTS releases as detailed in the vulnerability report.
What type of vulnerability is CVE-2025-46676?
CVE-2025-46676 is an exposure of sensitive information vulnerability that can lead to unauthorized access to sensitive data.
Who is impacted by CVE-2025-46676?
Organizations using affected versions of Dell PowerProtect Data Domain are at risk from CVE-2025-46676.