Use of Insecure Cryptographic Algorithm in Dell PowerProtect Data Domain
CVE-2025-43913

5.3MEDIUM

What is CVE-2025-43913?

The Dell PowerProtect Data Domain, operating on several versions of the DD OS, is affected by a vulnerability involving the use of an insecure cryptographic algorithm. This flaw enables unauthenticated attackers with remote access to potentially exploit the system, leading to information disclosure. Such exploitation may facilitate phishing attacks, where attackers trick users into revealing sensitive information, thus posing significant risks to the security and integrity of data managed by affected systems.

Affected Version(s)

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023 7.10.1.0 < 7.10.1.70

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024 7.13.1.0 < 7.13.1.40

PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025 8.3.1.0 < 8.3.1.10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43913 : Use of Insecure Cryptographic Algorithm in Dell PowerProtect Data Domain