Path Traversal Vulnerability in Dell PowerProtect Data Domain
CVE-2025-43907

6.5MEDIUM

What is CVE-2025-43907?

Dell PowerProtect Data Domain with various versions of Data Domain Operating System is affected by a path traversal vulnerability. A low privileged attacker with remote access may exploit this flaw to gain unauthorized access to sensitive information, raising significant security concerns for users. This exposure stresses the importance of implementing security updates and maintaining robust system configurations to safeguard against potential attacks.

Affected Version(s)

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023 7.10.1.0 < 7.10.1.70

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024 7.13.1.0 < 7.13.1.40

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025 8.3.1.0 < 8.3.1.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43907 : Path Traversal Vulnerability in Dell PowerProtect Data Domain