Command Injection Vulnerability in Dell PowerProtect Data Domain Products
CVE-2025-43905

4.3MEDIUM

What is CVE-2025-43905?

A vulnerability exists in Dell PowerProtect Data Domain systems due to an improper neutralization of argument delimiters, allowing a low privileged attacker with remote access to inject commands. If exploited, this flaw can lead to Denial of Service, impacting system availability and data protection capabilities.

Affected Version(s)

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023 7.10.1.0 < 7.10.1.70

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024 7.13.1.0 < 7.13.1.40

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025 8.3.1.0 < 8.3.1.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43905 : Command Injection Vulnerability in Dell PowerProtect Data Domain Products