cbcvebase.

Dell Powerprotect Data Domain vulnerabilities

57 known vulnerabilities affecting dell/powerprotect_data_domain.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH25MEDIUM26LOW3

Vulnerabilities

Page 2 of 3
CVE-2025-46606P3HIGHCVSS 7.2fixed in 8.6.0.0 or later2026-04-17
CVE-2025-46606 [HIGH] CWE-307 CVE-2025-46606: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2025-46607P3HIGHCVSS 7.2fixed in 8.6.0.0 or later2026-04-17
CVE-2025-46607 [HIGH] CWE-287 CVE-2025-46607: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-26355P3MEDIUMCVSS 6.5fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-26355 [MEDIUM] CWE-78 CVE-2026-26355: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged atta
nvd
CVE-2026-23853P3HIGHCVSS 8.4fixed in 8.6.0.0 or laterfixed in 8.3.1.20 or later+2 more2026-04-17
CVE-2026-23853 [HIGH] CWE-1391 CVE-2026-23853: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vul
nvd
CVE-2026-53482P3HIGHCVSS 7.5fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-08
CVE-2026-53482 [HIGH] CWE-190 CVE-2026-53482: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulne
nvd
CVE-2025-46605P3HIGHCVSS 7.2fixed in 8.6.0.0 or later2026-04-17
CVE-2025-46605 [HIGH] CWE-384 CVE-2025-46605: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2023-44277P3HIGHCVSS 7.8fixed in 6.2.1.110≥ 7.0, < 7.12.0.02023-12-14
CVE-2023-44277 [HIGH] CWE-78 CVE-2023-44277: Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable appli
nvd
CVE-2026-49813P3MEDIUMCVSS 6.7fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-49813 [MEDIUM] CWE-78 CVE-2026-49813: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged atta
nvd
CVE-2026-35072P3MEDIUMCVSS 6.7fixed in 8.6.1.10, 8.7.0.1 or laterfixed in 8.3.1.30 or later+2 more2026-04-17
CVE-2026-35072 [MEDIUM] CWE-78 CVE-2026-35072: Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A high privileged attacker wi
nvd
CVE-2023-44285P3HIGHCVSS 7.8fixed in 6.2.1.110≥ 7.0, < 7.12.0.02023-12-14
CVE-2023-44285 [HIGH] CWE-1220 CVE-2023-44285: Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.
nvd
CVE-2026-35073P3MEDIUMCVSS 6.7fixed in 8.7.0.1 or laterfixed in 8.3.1.30 or later+1 more2026-04-17
CVE-2026-35073 [MEDIUM] CWE-78 CVE-2026-35073: Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command injection vulnerability. A high privileged attacker with local access
nvd
CVE-2026-35074P3MEDIUMCVSS 6.7fixed in 8.6.1.10, 8.7.0.1 or laterfixed in 8.3.1.30 or later+2 more2026-04-17
CVE-2026-35074 [MEDIUM] CWE-78 CVE-2026-35074: Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access
nvd
CVE-2025-46641P3MEDIUMCVSS 6.6fixed in 8.6.0.0 or later2026-04-17
CVE-2025-46641 [MEDIUM] CWE-287 CVE-2025-46641: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
nvd
CVE-2026-46463P3MEDIUMCVSS 6.5fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-46463 [MEDIUM] CWE-190 CVE-2026-46463: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vul
nvd
CVE-2026-54483P3MEDIUMCVSS 6.7fixed in 8.7.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-03
CVE-2026-54483 [MEDIUM] CWE-78 CVE-2026-54483: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged atta
nvd
CVE-2026-23777P3MEDIUMCVSS 6.5≥ 7.13.1.0, ≤ 7.13.1.50≥ 8.3.1.0, ≤ 8.3.1.20+4 more2026-04-17
CVE-2026-23777 [MEDIUM] CWE-200 CVE-2026-23777: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an exposure of sensitive information to an unauthorized actor vulnerability. A low privileged attacker with remote acces
nvd
CVE-2026-26951P3MEDIUMCVSS 6.7fixed in 8.6.1.10, 8.7.0.0 or laterfixed in 8.3.1.30 or later+2 more2026-04-20
CVE-2026-26951 [MEDIUM] CWE-121 CVE-2026-26951: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with
nvd
CVE-2026-23779P3MEDIUMCVSS 6.7fixed in 8.6.0.0 or laterfixed in 8.3.1.20 or later+2 more2026-04-17
CVE-2026-23779 [MEDIUM] CWE-77 CVE-2026-23779: Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabil
nvd
CVE-2026-35153P3MEDIUMCVSS 6.7fixed in 8.6.1.10, 8.7.0.1 or laterfixed in 8.3.1.30 or later+2 more2026-04-17
CVE-2026-35153 [MEDIUM] CWE-88 CVE-2026-35153: Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local
nvd
CVE-2026-41122P4HIGHCVSS 7.1fixed in 8.8.0.0 or laterfixed in 8.6.1.20 or later+2 more2026-07-08
CVE-2026-41122 [HIGH] CWE-79 CVE-2026-41122: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerabil
nvd
Dell Powerprotect Data Domain vulnerabilities | cvebase