Path Traversal Vulnerability in Dell PowerProtect Data Domain
CVE-2025-43907
Key Information:
- Vendor
Dell
- Status
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Of Feature Release
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Lts2025
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Lts2024
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Lts2023
- Vendor
- CVE Published:
- 7 October 2025
What is CVE-2025-43907?
Dell PowerProtect Data Domain with various versions of Data Domain Operating System is affected by a path traversal vulnerability. A low privileged attacker with remote access may exploit this flaw to gain unauthorized access to sensitive information, raising significant security concerns for users. This exposure stresses the importance of implementing security updates and maintaining robust system configurations to safeguard against potential attacks.
Affected Version(s)
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023 7.10.1.0 < 7.10.1.70
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024 7.13.1.0 < 7.13.1.40
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025 8.3.1.0 < 8.3.1.10