cbcvebase.

Dell Data Domain Operating System vulnerabilities

99 known vulnerabilities affecting dell/data_domain_operating_system.

Total CVEs
99
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH38MEDIUM52LOW5

Vulnerabilities

Page 1 of 5
CVE-2025-36594P2CRITICALCVSS 9.8≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.30+1 more2025-08-04
CVE-2025-36594 [CRITICAL] CWE-290 CVE-2025-36594: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could pote
nvd
CVE-2026-26354P2CRITICALCVSS 9.8≥ 7.7.1.0, < 7.13.1.60≥ 7.14.0.0, < 8.3.1.20+1 more2026-04-22
CVE-2026-26354 [CRITICAL] CWE-121 CVE-2026-26354: Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1 Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain a stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this
nvd
CVE-2026-53483P2CRITICALCVSS 9.8≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+2 more2026-07-07
CVE-2026-53483 [CRITICAL] CWE-287 CVE-2026-53483: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l
nvd
CVE-2026-53481P2CRITICALCVSS 9.8≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+2 more2026-07-07
CVE-2026-53481 [CRITICAL] CWE-22 CVE-2026-53481: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with
nvd
CVE-2026-26944P2HIGHCVSS 8.8≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-20
CVE-2026-26944 [HIGH] CWE-306 CVE-2026-26944: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary comman
nvd
CVE-2025-29987P2HIGHCVSS 8.8≥ 7.10.1.0, < 7.10.1.60≥ 7.13.1.0, < 7.13.1.25+1 more2025-04-03
CVE-2025-29987 [HIGH] CWE-1220 CVE-2025-29987: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 c Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
nvd
CVE-2024-37140P2HIGHCVSS 8.8fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-37140 [HIGH] CWE-78 CVE-2024-37140: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the
nvd
CVE-2026-56086P3HIGHCVSS 8.8≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+1 more2026-07-08
CVE-2026-56086 [HIGH] CWE-863 CVE-2026-56086: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,
nvd
CVE-2026-23776P3HIGHCVSS 8.8≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-17
CVE-2026-23776 [HIGH] CWE-295 CVE-2026-23776: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low privileged attacker with remote acce
nvd
CVE-2026-49814P3HIGHCVSS 7.2≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-49814 [HIGH] CWE-78 CVE-2026-49814: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attack
nvd
CVE-2026-26943P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-20
CVE-2026-26943 [HIGH] CWE-78 CVE-2026-26943: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root pri
nvd
CVE-2026-53479P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+2 more2026-07-07
CVE-2026-53479 [HIGH] CWE-78 CVE-2026-53479: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged
nvd
CVE-2026-26942P3HIGHCVSS 7.2≥ 7.7.1.0, < 8.6.1.02026-04-20
CVE-2026-26942 [HIGH] CWE-78 CVE-2026-26942: Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Spe Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
nvd
CVE-2024-29176P3HIGHCVSS 8.8≥ 7.0, < 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+2 more2024-06-26
CVE-2024-29176 [HIGH] CWE-787 CVE-2024-29176: Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Wri Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
nvd
CVE-2025-46645P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.10.1.80≥ 7.13.1.0, < 7.13.1.50+2 more2026-01-09
CVE-2025-46645 [HIGH] CWE-78 CVE-2025-46645: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command
nvd
CVE-2026-49815P3HIGHCVSS 7.2≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-49815 [HIGH] CWE-78 CVE-2026-49815: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attack
nvd
CVE-2026-23774P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.13.1.50≥ 7.14.0.0, < 8.3.1.20+1 more2026-04-20
CVE-2026-23774 [HIGH] CWE-78 CVE-2026-23774: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnera
nvd
CVE-2026-53478P3HIGHCVSS 7.2≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-53478 [HIGH] CWE-78 CVE-2026-53478: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged attack
nvd
CVE-2026-24506P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-20
CVE-2026-24506 [HIGH] CWE-78 CVE-2026-24506: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root.
nvd
CVE-2026-22761P3HIGHCVSS 7.2≥ 7.7.1.0, < 8.6.1.02026-04-20
CVE-2026-22761 [HIGH] CWE-78 CVE-2026-22761: Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
nvd
Dell Data Domain Operating System vulnerabilities | cvebase