Vulnerability Details CVE-2025-29987
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-29987
-
cpe:2.3:a:dell:powerprotect_data_domain:-
-
cpe:2.3:a:dell:powerprotect_data_domain:7.10.1.20
-
cpe:2.3:a:dell:powerprotect_data_domain:7.10.1.30
-
cpe:2.3:a:dell:powerprotect_data_domain:7.7.5.30
-
cpe:2.3:a:dell:powerprotect_data_domain:7.7.5.40
-
cpe:2.3:a:dell:powerprotect_data_domain:7.7.6
-
cpe:2.3:h:dell:powerprotect_dm5500:-
-
cpe:2.3:o:dell:data_domain_operating_system:7.10.1.0
-
cpe:2.3:o:dell:data_domain_operating_system:7.10.1.30
-
cpe:2.3:o:dell:data_domain_operating_system:7.10.1.40
-
cpe:2.3:o:dell:data_domain_operating_system:7.10.1.50
-
cpe:2.3:o:dell:data_domain_operating_system:7.13.1.0
-
cpe:2.3:o:dell:data_domain_operating_system:7.13.1.10
-
cpe:2.3:o:dell:data_domain_operating_system:7.13.1.20
-
cpe:2.3:o:dell:data_domain_operating_system:8.3.0.0
-
cpe:2.3:o:dell:data_domain_operating_system:8.3.0.10
-
cpe:2.3:o:dell:powerprotect_dm5500_firmware:*