CVE-2025-36594
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: security_alert@emc.com (Secondary)
Description
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.
Affected (3)
Products: Dell: Data Domain Operating System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.13.1.0 to 7.13.1.30 |
References (1)
Source: security_alert@emc.com
Vendor Advisory
Timeline
No history available yet.