CVE-2025-30099OS Command Injection in Dell Data Domain Operating System

Severity
7.8HIGHNVD
EPSS
0.0%
top 90.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privi

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5dell/powerprotect_data_domain_feature_release7.7.1.08.1.0.10
NVDdell/data_domain_operating_system7.7.1.07.10.1.60+2
CVEListV5dell/powerprotect_data_domain_lts20247.13.1.07.13.1.25
CVEListV5dell/powerprotect_data_domain_lts_20237.10.1.07.10.1.50

🔴Vulnerability Details

2
GHSA
GHSA-6q38-9xf9-365m: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 72025-08-04
CVEList
CVE-2025-30099: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 72025-08-04
CVE-2025-30099 — OS Command Injection in Dell | cvebase