CVE-2025-30098OS Command Injection in Dell Data Domain Operating System

Severity
6.7MEDIUMNVD
EPSS
0.0%
top 96.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root priv

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5dell/powerprotect_data_domain_feature_release7.7.1.08.1.0.10
NVDdell/data_domain_operating_system7.7.1.07.10.1.60+2
CVEListV5dell/powerprotect_data_domain_lts20247.13.1.07.13.1.25
CVEListV5dell/powerprotect_data_domain_lts_20237.10.1.07.10.1.50

🔴Vulnerability Details

2
GHSA
GHSA-xhxf-jxm8-m429: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 72025-08-04
CVEList
CVE-2025-30098: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 72025-08-04
CVE-2025-30098 — OS Command Injection in Dell | cvebase