Authentication Algorithm Vulnerability in Dell PowerProtect Data Domain
CVE-2025-43727
7.5HIGH
Key Information:
What is CVE-2025-43727?
The Dell PowerProtect Data Domain systems running specific versions of the Data Domain Operating System contain a vulnerability due to an incorrect implementation of the authentication algorithm within the RestAPI. This flaw could allow an unauthenticated attacker with remote access to successfully exploit the system, potentially leading to unauthorized access and compromise of sensitive data.
Affected Version(s)
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023 7.10.1.0 < 7.10.1.60
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024 7.13.1.0 < 7.13.1.30
PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release 7.7.1.0 < 8.3.0.10