High severity8.8NVD Advisory· Published Apr 3, 2025· Updated Jun 17, 2026
CVE-2025-29987
CVE-2025-29987
Description
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:lts:*:*:*range: <7.10.1.60
- (no CPE)range: <8.3.0.15
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*range: >=7.10.1.0,<7.10.1.60
- (no CPE)range: <8.3.0.15
- cpe:2.3:o:dell:powerprotect_dm5500_firmware:*:*:*:*:*:*:*:*Range: >=5.12,<5.19.0.0
- Dell/DD OS 7.10v5Range: 7.10.1.0
- Dell/DD OS 7.13v5Range: 7.13.1.0
- Range: N/A
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.