Use of Insecure Cryptographic Algorithm in Dell PowerProtect Data Domain
CVE-2025-43913
Key Information:
- Vendor
Dell
- Status
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Of Feature Release
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Lts2025
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Lts2024
- Powerprotect Data Domain With Data Domain Operating System (dd Os) Lts2023
- Vendor
- CVE Published:
- 7 October 2025
What is CVE-2025-43913?
The Dell PowerProtect Data Domain, operating on several versions of the DD OS, is affected by a vulnerability involving the use of an insecure cryptographic algorithm. This flaw enables unauthenticated attackers with remote access to potentially exploit the system, leading to information disclosure. Such exploitation may facilitate phishing attacks, where attackers trick users into revealing sensitive information, thus posing significant risks to the security and integrity of data managed by affected systems.
Affected Version(s)
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023 7.10.1.0 < 7.10.1.70
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024 7.13.1.0 < 7.13.1.40
PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025 8.3.1.0 < 8.3.1.10