CVE-2025-29987
—CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
Description
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
- Vendors
- dell
- Products
- powerprotect data domain, data domain operating system, powerprotect dm5500 firmware
- Weakness
- CWE-1220
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.