PT-2025-41157 · Dell · Dell Powerprotect Data Domain Lts 2023+3

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-43934

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Domain versions 7.7.1.0 through 8.3.0.15 Dell PowerProtect Data Domain LTS2025 version 8.3.1.0 Dell PowerProtect Data Domain LTS2024 versions 7.13.1.0 through 7.13.1.30 Dell PowerProtect Data Domain LTS 2023 versions 7.10.1.0 through 7.10.1.60
Description The software contains an Improper Limitation of a Pathname to a Restricted Directory issue, also known as a 'Path Traversal' condition. An attacker with high privileges and local access could potentially cause a denial of service or gain unauthorized access.
Recommendations Update Dell PowerProtect Data Domain versions to a version later than 8.3.0.15. Update Dell PowerProtect Data Domain LTS2025 to a version later than 8.3.1.0. Update Dell PowerProtect Data Domain LTS2024 to a version later than 7.13.1.30. Update Dell PowerProtect Data Domain LTS 2023 to a version later than 7.10.1.60.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-12856
CVE-2025-43934

Affected Products

Dell Powerprotect Data Domain
Dell Powerprotect Data Domain Lts 2023
Dell Powerprotect Data Domain Lts2024
Dell Powerprotect Data Domain Lts2025