Dell Data Domain Operating System vulnerabilities
99 known vulnerabilities affecting dell/data_domain_operating_system.
Total CVEs
99
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH38MEDIUM52LOW5
Vulnerabilities
Page 5 of 5
CVE-2024-53296P4MEDIUMCVSS 4.9≥ 7.10.1.0, < 7.10.1.50≥ 7.13.1.0, < 7.13.1.202025-02-01
CVE-2024-53296 [MEDIUM] CWE-121 CVE-2024-53296: Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow
Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in the RestAPI. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
nvd
CVE-2024-29173P4MEDIUMCVSS 4.9≥ 7.0, ≤ 7.13fixed in 5.16.0.02024-06-26
CVE-2024-29173 [MEDIUM] CWE-918 CVE-2024-29173: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Ser
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client.
nvd
CVE-2024-29174P4MEDIUMCVSS 4.4fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-29174 [MEDIUM] CWE-89 CVE-2024-29174: Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection v
Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.
nvd
CVE-2026-41123P4MEDIUMCVSS 4.3≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+1 more2026-07-03
CVE-2026-41123 [MEDIUM] CWE-284 CVE-2026-41123: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this
nvd
CVE-2026-28263P4MEDIUMCVSS 4.8≥ 7.7.1.0, ≤ 8.5.0.02026-04-17
CVE-2026-28263 [MEDIUM] CWE-79 CVE-2026-28263: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker with remote access could potentially exploit this vulner
nvd
CVE-2026-44269P4MEDIUMCVSS 4.4≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-44269 [MEDIUM] CWE-59 CVE-2026-44269: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('link following') vulnerability. A high privileged attacker with local access could
nvd
CVE-2026-41124P4MEDIUMCVSS 4.4≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+1 more2026-07-03
CVE-2026-41124 [MEDIUM] CWE-22 CVE-2026-41124: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with lo
nvd
CVE-2024-28973P4MEDIUMCVSS 4.8≥ 7.0, ≤ 7.13fixed in 5.16.0.02024-06-26
CVE-2024-28973 [MEDIUM] CWE-79 CVE-2024-28973: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Sto
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scripting Vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a high privileged victim user
nvd
CVE-2026-46468P4MEDIUMCVSS 4.4≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-46468 [MEDIUM] CWE-59 CVE-2026-46468: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged attacker with local access could
nvd
CVE-2025-43910P4MEDIUMCVSS 4.4≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-43910 [MEDIUM] CWE-121 CVE-2025-43910: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain a Stack-based Buffer Overflow vulnerability in the DDSH CLI. A high privileged
nvd
CVE-2025-45375P4MEDIUMCVSS 4.4≥ 7.7.1.0, < 7.10.1.70≥ 7.13.1.0, < 7.13.1.40+2 more2025-10-07
CVE-2025-45375 [MEDIUM] CWE-121 CVE-2025-45375: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain a Stack-based Buffer Overflow vulnerability. A high privileged attacker with l
nvd
CVE-2026-44268P4MEDIUMCVSS 4.4≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-44268 [MEDIUM] CWE-732 CVE-2026-44268: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect permission Assignment for critical resource vulnerability. A high privileged attacker with local access could potenti
nvd
CVE-2026-46730P4MEDIUMCVSS 4.2≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-46730 [MEDIUM] CWE-863 CVE-2026-46730: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabilit
nvd
CVE-2025-46643P4MEDIUMCVSS 4.4≥ 7.7.1.0, < 7.10.1.80≥ 7.13.1.0, < 7.13.1.50+2 more2026-01-09
CVE-2025-46643 [MEDIUM] CWE-122 CVE-2025-46643: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overflow vulnerability. A high privileged attacker with lo
nvd
CVE-2024-37141P4LOWCVSS 3.5fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-37141 [LOW] CWE-601 CVE-2024-37141: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an op
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
nvd
CVE-2026-53480P4LOWCVSS 2.7≥ 7.7.1.0, < 7.13.1.80≥ 7.14.0.0, < 8.3.1.40+2 more2026-07-08
CVE-2026-53480 [LOW] CWE-22 CVE-2026-53480: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remot
nvd
CVE-2026-56085P4LOWCVSS 3.3≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-56085 [LOW] CWE-908 CVE-2026-56085: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabil
nvd
CVE-2026-46466P4LOWCVSS 2.7≥ 7.7.1.0, ≤ 7.13.1.70≥ 8.0.0.0, ≤ 8.3.1.30+1 more2026-07-03
CVE-2026-46466 [LOW] CWE-348 CVE-2026-46466: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabili
nvd
CVE-2024-29177P4LOWCVSS 2.7fixed in 7.7.5.40≥ 7.8.0.0, < 7.10.1.30+1 more2024-06-26
CVE-2024-29177 [LOW] CWE-532 CVE-2024-29177: Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a dis
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the reuse of disclosed information to gain unauthorized access to the application report.
nvd
← Previous5 / 5