ZeroHour

CVE-2025-29987

CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

Vendors
dell
Products
powerprotect data domain, data domain operating system, powerprotect dm5500 firmware
Weakness
CWE-1220
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.