8.8
CVE-2025-29987
- EPSS 0.41%
- Veröffentlicht 03.04.2025 16:15:36
- Zuletzt bearbeitet 22.01.2026 20:53:27
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Powerprotect Data Domain SwEditionlts Version < 7.10.1.60
Dell ≫ Data Domain Operating System Version >= 7.10.1.0 < 7.10.1.60
Dell ≫ Data Domain Operating System Version >= 7.13.1.0 < 7.13.1.25
Dell ≫ Data Domain Operating System Version >= 8.3.0.0 < 8.3.0.15
Dell ≫ Powerprotect Dm5500 Firmware Version >= 5.12 < 5.19.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.61 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security_alert@emc.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-1220 Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.