Authentication Bypass Vulnerability in Dell PowerProtect Data Domain
CVE-2025-36594

9.8CRITICAL

What is CVE-2025-36594?

The Dell PowerProtect Data Domain systems are vulnerable to an authentication bypass by spoofing. This vulnerability allows an unauthenticated attacker with remote access to exploit the system, potentially bypassing protection mechanisms. The attacker can create unauthorized accounts that may expose sensitive customer information and compromise the integrity and availability of the system. This critical security risk highlights the importance of regular updates and robust security measures in safeguarding data.

Affected Version(s)

PowerProtect Data Domain Feature Release 7.7.1.0 <= 8.3.0.15

PowerProtect Data Domain LTS 2023 7.10.1.0 <= 7.10.1.60

PowerProtect Data Domain LTS2024 7.13.1.0 <= 7.13.1.25

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.