cbcvebase.

Dell Data Domain Operating System vulnerabilities

99 known vulnerabilities affecting dell/data_domain_operating_system.

Total CVEs
99
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH38MEDIUM52LOW5

Vulnerabilities

Page 2 of 5
CVE-2025-43727P3HIGHCVSS 7.5≥ 7.7.1.0, < 7.10.1.60≥ 7.13.1.0, < 7.13.1.30+1 more2025-10-07
CVE-2025-43727 [HIGH] CWE-303 CVE-2025-43727: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an incorrect Implementation of Authentication Algorithm vulnerability in the RestAPI. An unauthenticated attacker
nvd
CVE-2025-30099P3HIGHCVSS 7.8≥ 7.7.1.0, < 7.10.1.60≥ 7.11.0.0, < 7.13.1.30+1 more2025-08-04
CVE-2025-30099 [HIGH] CWE-78 CVE-2025-30099: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the
nvd
CVE-2026-23778P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.13.1.50≥ 7.14.0.0, < 8.3.1.20+1 more2026-04-17
CVE-2026-23778 [HIGH] CWE-77 CVE-2026-23778: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabili
nvd
CVE-2026-24504P3HIGHCVSS 7.2≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-20
CVE-2026-24504 [HIGH] CWE-20 CVE-2026-24504: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with roo
nvd
CVE-2026-24505P3HIGHCVSS 7.2≥ 7.7.1.0, < 8.6.1.02026-04-20
CVE-2026-24505 [HIGH] CWE-20 CVE-2026-24505: Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnera Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
nvd
CVE-2025-43889P3HIGHCVSS 7.5≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+1 more2025-10-07
CVE-2025-43889 [HIGH] CWE-22 CVE-2025-43889: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release Versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UI. An unauthent
nvd
CVE-2025-43891P3HIGHCVSS 7.5≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43891 [HIGH] CWE-327 CVE-2025-43891: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an use of a Broken or Risky Cryptographic Algorithm vulnerability in the Authent
nvd
CVE-2025-46606P3HIGHCVSS 7.2≥ 8.4.0.0, < 8.6.0.02026-04-17
CVE-2025-46606 [HIGH] CWE-307 CVE-2025-46606: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2025-46607P3HIGHCVSS 7.2≥ 8.4.0.0, ≤ 8.5.0.02026-04-17
CVE-2025-46607 [HIGH] CWE-287 CVE-2025-46607: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-23853P3HIGHCVSS 8.4≥ 7.7.1.0, < 7.13.1.60≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-17
CVE-2026-23853 [HIGH] CWE-1391 CVE-2026-23853: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vul
nvd
CVE-2026-53482P3HIGHCVSS 7.5≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+2 more2026-07-08
CVE-2026-53482 [HIGH] CWE-190 CVE-2026-53482: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulne
nvd
CVE-2025-46605P3HIGHCVSS 7.2≥ 8.4.0.0, < 8.6.0.02026-04-17
CVE-2025-46605 [HIGH] CWE-384 CVE-2025-46605: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2025-43912P3HIGHCVSS 7.5≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43912 [HIGH] CWE-122 CVE-2025-43912: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain a Heap-based Buffer Overflow vulnerability. An unauthenticated attacker with rem
nvd
CVE-2025-43909P3HIGHCVSS 7.5≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43909 [HIGH] CWE-327 CVE-2025-43909: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Use of a Broken or Risky Cryptographic Algorithm vulnerability in the DD boos
nvd
CVE-2026-26355P3MEDIUMCVSS 6.5≥ 7.7.1.0, < 7.13.1.80≥ 8.3.1.0, < 8.3.1.40+1 more2026-07-03
CVE-2026-26355 [MEDIUM] CWE-78 CVE-2026-26355: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged atta
nvd
CVE-2025-36568P3HIGHCVSS 7.8≥ 7.7.1.0, < 7.13.1.60≥ 7.14.0.0, < 8.3.1.30+1 more2026-04-17
CVE-2025-36568 [HIGH] CWE-522 CVE-2025-36568: Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LT Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,
nvd
CVE-2025-43914P3HIGHCVSS 7.8≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, ≤ 7.13.1.40+2 more2025-10-07
CVE-2025-43914 [HIGH] CWE-266 CVE-2025-43914: Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 t Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local ac
nvd
CVE-2024-48010P3HIGHCVSS 7.2≥ 7.7.0.0, < 7.7.5.50≥ 7.10.0.0, < 7.10.1.40+2 more2024-11-08
CVE-2024-48010 [HIGH] CWE-284 CVE-2024-48010: Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an acc Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privilege on the application.
nvd
CVE-2025-22475P3HIGHCVSS 7.5≥ 7.10.1.0, < 7.10.1.50≥ 7.13.1.0, < 7.13.1.10+1 more2025-02-04
CVE-2025-22475 [HIGH] CWE-1240 CVE-2025-22475: Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a C Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could potentially exploit this vulnerability, leading to Information tampering.
nvd
CVE-2026-35072P3MEDIUMCVSS 6.7≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+2 more2026-04-17
CVE-2026-35072 [MEDIUM] CWE-78 CVE-2026-35072: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 th Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A high privileged attacker with local access could potentially expl
nvd
Dell Data Domain Operating System vulnerabilities | cvebase