OS Command Injection Vulnerability in Dell PowerProtect Data Domain
CVE-2025-30097

6.7MEDIUM

What is CVE-2025-30097?

The vulnerability in Dell PowerProtect Data Domain systems stems from an improper neutralization of special elements utilized in OS commands, specifically within the DDSH CLI interface. This allows a high-privileged attacker with local access to potentially execute arbitrary commands with root-level privileges, posing a significant risk to the integrity and security of the affected systems.

Affected Version(s)

PowerProtect Data Domain Feature Release 7.7.1.0 <= 8.1.0.10

PowerProtect Data Domain LTS 2023 7.10.1.0 <= 7.10.1.50

PowerProtect Data Domain LTS2024 7.13.1.0 <= 7.13.1.25

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.