CVE-2025-30097

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges
Configurations

No configuration.

History

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) Dell PowerProtect Data Domain con el sistema operativo Data Domain (DD OS) de las versiones Feature Release 7.7.1.0 a 8.1.0.10, LTS2024 de la 7.13.1.0 a la 7.13.1.25 y LTS 2023 de la 7.10.1.0 a la 7.10.1.50, presenta una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('inyección de comandos del sistema operativo') en la CLI de DDSH. Un atacante con privilegios elevados y acceso local podría aprovechar esta vulnerabilidad para ejecutar comandos arbitrarios con privilegios de root.

04 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 15:15

Updated : 2025-08-05 14:34


NVD link : CVE-2025-30097

Mitre link : CVE-2025-30097

CVE.ORG link : CVE-2025-30097


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')