Improper Authentication Flaw in Dell PowerProtect Data Domain
CVE-2025-46607

6.6MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
17 April 2026

What is CVE-2025-46607?

The Dell PowerProtect Data Domain, running on Feature Release versions 8.4 through 8.5, has a vulnerability that allows attackers with high privileges and remote access to exploit improper authentication mechanisms. This could potentially lead to unauthorized access, posing risks to the integrity and confidentiality of sensitive data. Organizations using the affected software should assess their systems immediately to mitigate this security concern.

Affected Version(s)

PowerProtect Data Domain 0 < 8.6.0.0 or later

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.