VYPR
High severity8.8NVD Advisory· Published Apr 3, 2025· Updated Jun 17, 2026

CVE-2025-29987

CVE-2025-29987

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:lts:*:*:*+ 1 more
    • cpe:2.3:a:dell:powerprotect_data_domain:*:*:*:*:lts:*:*:*range: <7.10.1.60
    • (no CPE)range: <8.3.0.15
  • cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*range: >=7.10.1.0,<7.10.1.60
    • (no CPE)range: <8.3.0.15
  • cpe:2.3:o:dell:powerprotect_dm5500_firmware:*:*:*:*:*:*:*:*
    Range: >=5.12,<5.19.0.0
  • Dell/DD OS 7.10v5
    Range: 7.10.1.0
  • Dell/DD OS 7.13v5
    Range: 7.13.1.0
  • Dell/DD OScpe-rescue
    Range: 7.7.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.