CVE-2025-36594Authentication Bypass by Spoofing in Dell Data Domain Operating System

Severity
9.8CRITICALNVD
EPSS
0.4%
top 38.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose cus

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5dell/powerprotect_data_domain_feature_release7.7.1.08.3.0.15
NVDdell/data_domain_operating_system7.7.1.07.10.1.70+2
CVEListV5dell/powerprotect_data_domain_lts20247.13.1.07.13.1.25
CVEListV5dell/powerprotect_data_domain_lts_20237.10.1.07.10.1.60

🔴Vulnerability Details

2
GHSA
GHSA-3r2v-4fp3-8g3h: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 72025-08-04
CVEList
CVE-2025-36594: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 72025-08-04
CVE-2025-36594 — Authentication Bypass by Spoofing | cvebase