Dell Data Domain Operating System vulnerabilities
99 known vulnerabilities affecting dell/data_domain_operating_system.
Total CVEs
99
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH38MEDIUM52LOW5
Vulnerabilities
Page 4 of 5
CVE-2026-26951P3MEDIUMCVSS 6.7≥ 7.7.1.0, < 7.13.1.70≥ 8.3.1.0, < 8.3.1.30+1 more2026-04-20
CVE-2026-26951 [MEDIUM] CWE-121 CVE-2026-26951: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with
nvd
CVE-2025-43905P3MEDIUMCVSS 6.5≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43905 [MEDIUM] CWE-88 CVE-2025-43905: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Neutralization of Argument Delimiters in a Command ('Argument Injec
nvd
CVE-2024-45759P3HIGHCVSS 7.3≥ 7.7.1.0, < 7.7.5.50≥ 7.10.0.0, < 7.10.1.40+2 more2024-11-08
CVE-2024-45759 [HIGH] CWE-266 CVE-2024-45759: Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contai
Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to unauthorized execution of certain commands to overwrite system config of the application. Exploitation may lead to deni
nvd
CVE-2026-23779P3MEDIUMCVSS 6.7≥ 7.7.1.0, < 7.13.1.50≥ 8.3.1.0, < 8.3.1.20+1 more2026-04-17
CVE-2026-23779 [MEDIUM] CWE-77 CVE-2026-23779: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabil
nvd
CVE-2026-35153P3MEDIUMCVSS 6.7≥ 7.7.1.0, < 7.13.1.70≥ 7.14.0.0, < 8.3.1.30+2 more2026-04-17
CVE-2026-35153 [MEDIUM] CWE-88 CVE-2026-35153: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 th
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this
nvd
CVE-2025-36565P3MEDIUMCVSS 6.7≥ 7.7.1.0, < 7.10.1.60≥ 7.13.1.0, < 7.13.1.30+1 more2025-10-07
CVE-2025-36565 [MEDIUM] CWE-88 CVE-2025-36565: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A high priv
nvd
CVE-2025-43913P3MEDIUMCVSS 6.5≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43913 [MEDIUM] CWE-327 CVE-2025-43913: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Use of a Broken or Risky Cryptographic Algorithm vulnerability in the DDOS.
nvd
CVE-2026-41122P4HIGHCVSS 7.1≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+2 more2026-07-08
CVE-2026-41122 [HIGH] CWE-79 CVE-2026-41122: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerabil
nvd
CVE-2024-37139P3MEDIUMCVSS 6.5fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-37139 [MEDIUM] CWE-664 CVE-2024-37139: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Im
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to temporary resource constraint of system application. Exploitation may lead
nvd
CVE-2024-48011P3MEDIUMCVSS 6.5≥ 7.0, < 7.7.5.502024-11-08
CVE-2024-48011 [MEDIUM] CWE-200 CVE-2024-48011: Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to a
Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2024-37138P4MEDIUMCVSS 6.8fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-37138 [MEDIUM] CWE-23 CVE-2024-37138: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC conta
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized file to the managed system.
nvd
CVE-2026-23775P4MEDIUMCVSS 5.7≥ 8.3.0.0, < 8.3.1.20≥ 8.4.0.0, < 8.6.0.02026-04-17
CVE-2026-23775 [MEDIUM] CWE-532 CVE-2026-23775: Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Releas
Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading
nvd
CVE-2024-29175P4MEDIUMCVSS 5.9fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-29175 [MEDIUM] CWE-327 CVE-2024-29175: Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an we
Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to man-in-the-middle attack that exposes sensitive session information.
nvd
CVE-2026-35154P4MEDIUMCVSS 6.7≥ 7.13.1.0, < 7.13.1.70≥ 8.3.0.0, < 8.3.1.30+1 more2026-04-20
CVE-2026-35154 [MEDIUM] CWE-269 CVE-2026-35154: Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions
Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability.
A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of p
nvd
CVE-2024-51534P4HIGHCVSS 7.1≥ 7.10.1.0, < 7.10.1.50≥ 7.13.1.0, < 7.13.1.20+1 more2025-02-01
CVE-2024-51534 [HIGH] CWE-29 CVE-2024-51534: Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path travers
Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service.
nvd
CVE-2025-43934P4MEDIUMCVSS 6.0≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43934 [MEDIUM] CWE-22 CVE-2025-43934: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal
nvd
CVE-2026-46465P4MEDIUMCVSS 5.5≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-46465 [MEDIUM] CWE-134 CVE-2026-46465: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially explo
nvd
CVE-2025-46676P4MEDIUMCVSS 4.9≥ 7.7.1.0, < 7.10.1.80≥ 7.13.1.0, < 7.13.1.50+2 more2026-01-09
CVE-2025-46676 [MEDIUM] CWE-200 CVE-2025-46676: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A
nvd
CVE-2026-46467P4MEDIUMCVSS 5.8≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-46467 [MEDIUM] CWE-532 CVE-2026-46467: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially e
nvd
CVE-2026-46464P4MEDIUMCVSS 4.9≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-46464 [MEDIUM] CWE-59 CVE-2026-46464: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged attacker with remote access coul
nvd