PT-2025-31816 · Dell · Dell Powerprotect Data Domain

Published

2025-08-04

·

Updated

2025-08-04

·

CVE-2025-30099

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Dell PowerProtect Data Domain versions 7.7.1.0 through 8.1.0.10

Dell PowerProtect Data Domain versions 7.13.1.0 through 7.13.1.25

Dell PowerProtect Data Domain versions 7.10.1.0 through 7.10.1.50

Description:

The Dell PowerProtect Data Domain contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Recommendations:

Update to a version later than 8.1.0.10.

Update to a version later than 7.13.1.25.

Update to a version later than 7.10.1.50.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-30099

Affected Products

Dell Powerprotect Data Domain