OS Command Injection Vulnerability in Dell PowerProtect Data Domain
CVE-2025-30097
6.7MEDIUM
Key Information:
- Vendor
Dell
- Status
- Vendor
- CVE Published:
- 4 August 2025
What is CVE-2025-30097?
The vulnerability in Dell PowerProtect Data Domain systems stems from an improper neutralization of special elements utilized in OS commands, specifically within the DDSH CLI interface. This allows a high-privileged attacker with local access to potentially execute arbitrary commands with root-level privileges, posing a significant risk to the integrity and security of the affected systems.
Affected Version(s)
PowerProtect Data Domain Feature Release 7.7.1.0 <= 8.1.0.10
PowerProtect Data Domain LTS 2023 7.10.1.0 <= 7.10.1.50
PowerProtect Data Domain LTS2024 7.13.1.0 <= 7.13.1.25