Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
References
Configurations
History
08 May 2026, 14:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:* | |
| References | () https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities - Vendor Advisory | |
| First Time |
Dell
Dell data Domain Operating System |
17 Apr 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-17 12:16
Updated : 2026-05-08 14:06
NVD link : CVE-2025-46605
Mitre link : CVE-2025-46605
CVE.ORG link : CVE-2025-46605
JSON object : View
Products Affected
dell
- data_domain_operating_system
CWE
CWE-384
Session Fixation
