CVE-2025-46605

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Configurations

Configuration 1 (hide)

cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

08 May 2026, 14:06

Type Values Removed Values Added
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities - Vendor Advisory
First Time Dell
Dell data Domain Operating System

17 Apr 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 12:16

Updated : 2026-05-08 14:06


NVD link : CVE-2025-46605

Mitre link : CVE-2025-46605

CVE.ORG link : CVE-2025-46605


JSON object : View

Products Affected

dell

  • data_domain_operating_system
CWE
CWE-384

Session Fixation