CVE-2025-29987

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:lts:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:powerprotect_dm5500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerprotect_dm5500:-:*:*:*:*:*:*:*

History

22 Jan 2026, 20:53

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000300899/dsa-2025-139-dell-technologies-powerprotect-data-domain-security-update-for-a-security-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000300899/dsa-2025-139-dell-technologies-powerprotect-data-domain-security-update-for-a-security-vulnerability - Vendor Advisory
CWE NVD-CWE-Other
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:powerprotect_dm5500:-:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:lts:*:*:*
cpe:2.3:o:dell:powerprotect_dm5500_firmware:*:*:*:*:*:*:*:*
First Time Dell data Domain Operating System
Dell powerprotect Data Domain
Dell powerprotect Dm5500 Firmware
Dell
Dell powerprotect Dm5500

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) Las versiones de Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) anteriores a la 8.3.0.15 presentan una vulnerabilidad de control de acceso con granularidad insuficiente. Un usuario autenticado de un cliente remoto de confianza podría aprovechar esta vulnerabilidad para ejecutar comandos arbitrarios con privilegios de root.

03 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 16:15

Updated : 2026-01-22 20:53


NVD link : CVE-2025-29987

Mitre link : CVE-2025-29987

CVE.ORG link : CVE-2025-29987


JSON object : View

Products Affected

dell

  • data_domain_operating_system
  • powerprotect_dm5500
  • powerprotect_dm5500_firmware
  • powerprotect_data_domain
CWE
CWE-1220

Insufficient Granularity of Access Control

NVD-CWE-Other