📦 Data Domain Operating System

by Dell

🔍 What is Data Domain Operating System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-36594

CRITICAL CVSS 9.8 Aug 4, 2025

An authentication bypass vulnerability in Dell PowerProtect Data Domain allows unauthenticated remote attackers to create accounts and bypass protection mechanisms. This affects systems running specif...

CVE-2025-43727

HIGH CVSS 7.5 Oct 7, 2025

An authentication bypass vulnerability in Dell PowerProtect Data Domain's RestAPI allows unauthenticated remote attackers to gain unauthorized access. This affects Data Domain Operating System (DD OS)...

CVE-2025-43914

HIGH CVSS 7.5 Oct 7, 2025

Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems contain an Incorrect Privilege Assignment vulnerability (CWE-266). A local attacker with low privileges could exploit this to gain unauth...

CVE-2025-30099

HIGH CVSS 7.8 Aug 4, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. Attackers with local low-privileged access can execute arbitrary commands with root privileges. Af...

CVE-2024-53295

HIGH CVSS 7.8 Feb 1, 2025

This vulnerability allows a local malicious user with low privileges on Dell PowerProtect DD systems to escalate their privileges through improper access control. Affected systems include Dell PowerPr...

CVE-2024-51534

HIGH CVSS 7.1 Feb 1, 2025

A local path traversal vulnerability in Dell PowerProtect DD allows low-privileged users to overwrite OS files, potentially causing denial of service. This affects Dell PowerProtect DD systems running...

CVE-2024-37140

HIGH CVSS 8.8 Jun 26, 2024

Dell PowerProtect DD versions before 8.0 contain an OS command injection vulnerability in an admin operation. A remote attacker with low privileges can execute arbitrary OS commands on the underlying ...

CVE-2024-29176

HIGH CVSS 8.8 Jun 26, 2024

Dell PowerProtect DD versions contain an out-of-bounds write vulnerability that allows low-privileged remote attackers to execute arbitrary code. This affects organizations using vulnerable versions o...

CVE-2025-46645

MEDIUM CVSS 6.5 Jan 9, 2026

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged attacker with remote access could execute arbitrary...

CVE-2025-46644

MEDIUM CVSS 6.0 Jan 9, 2026

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access could execute arbitrary commands on affected systems. Or...

CVE-2025-36567

MEDIUM CVSS 6.7 Oct 7, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access can execute arbitrary commands, potentially escalating t...

CVE-2025-36569

MEDIUM CVSS 6.7 Oct 7, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged attacker with local access could execute arbitrary ...

CVE-2025-36566

MEDIUM CVSS 6.7 Oct 7, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged attacker with local access could execute arbitrary ...

CVE-2025-45375

MEDIUM CVSS 4.4 Oct 7, 2025

A stack-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows high-privileged attackers with local access to cause denial of service. This affects organizations using ...

CVE-2025-43913

MEDIUM CVSS 5.3 Oct 7, 2025

Dell PowerProtect Data Domain systems running affected DD OS versions contain a broken cryptographic algorithm vulnerability. Unauthenticated remote attackers could exploit this to potentially disclos...

CVE-2025-43934

MEDIUM CVSS 6.0 Oct 7, 2025

This path traversal vulnerability in Dell PowerProtect Data Domain allows high-privileged local attackers to access restricted directories, potentially causing denial of service or unauthorized access...

CVE-2025-43912

MEDIUM CVSS 5.3 Oct 7, 2025

A heap-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows unauthenticated remote attackers to cause denial of service. This affects multiple Dell Data Domain Operat...

CVE-2025-43905

MEDIUM CVSS 4.3 Oct 7, 2025

This vulnerability allows low-privileged remote attackers to inject malicious arguments into commands on Dell PowerProtect Data Domain systems, potentially causing denial of service. It affects Data D...

CVE-2025-43907

MEDIUM CVSS 6.5 Oct 7, 2025

This CVE describes a path traversal vulnerability in Dell PowerProtect Data Domain systems where attackers can use '.../...//' sequences to access unauthorized files. Low-privileged remote attackers c...

CVE-2025-43908

MEDIUM CVSS 6.4 Oct 7, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access can execute arbitrary commands with root privileges. Aff...

CVE-2025-43889

MEDIUM CVSS 5.3 Oct 7, 2025

Dell PowerProtect Data Domain systems running vulnerable DD OS versions contain a path traversal vulnerability in the UI that allows unauthenticated remote attackers to access restricted directories. ...

CVE-2025-43891

MEDIUM CVSS 5.3 Oct 7, 2025

Dell PowerProtect Data Domain systems using vulnerable DD OS versions contain a broken cryptographic algorithm in authentication mechanisms. An unauthenticated remote attacker could exploit this to po...

CVE-2025-43906

MEDIUM CVSS 6.7 Oct 7, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged attacker with local access can execute arbitrary co...

CVE-2025-43911

MEDIUM CVSS 6.7 Oct 7, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged attacker with local access can execute arbitrary co...

CVE-2025-30096

MEDIUM CVSS 6.7 Aug 4, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. A high-privileged attacker with local access can execute arbitrary commands with root privileges. ...

CVE-2025-30097

MEDIUM CVSS 6.7 Aug 4, 2025

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. A high-privileged attacker with local access can execute arbitrary commands with root privileges. ...

CVE-2025-30098

MEDIUM CVSS 6.7 Aug 4, 2025

This vulnerability allows a high-privileged attacker with local access to execute arbitrary OS commands with root privileges on Dell PowerProtect Data Domain systems. It affects systems running specif...

CVE-2024-45759

MEDIUM CVSS 6.8 Nov 8, 2024

Dell PowerProtect Data Domain has a local privilege escalation vulnerability where authenticated low-privileged users can execute unauthorized commands to overwrite system configuration. This could le...

CVE-2024-37138

MEDIUM CVSS 4.1 Jun 26, 2024

Dell PowerProtect DD management console contains a relative path traversal vulnerability that allows authenticated high-privilege attackers to send unauthorized files to managed systems. This affects ...

CVE-2024-29175

MEDIUM CVSS 5.9 Jun 26, 2024

Dell PowerProtect Data Domain systems using weak cryptographic algorithms are vulnerable to man-in-the-middle attacks. Remote unauthenticated attackers can intercept and expose sensitive session infor...

CVE-2024-29173

MEDIUM CVSS 6.8 Jun 26, 2024

This SSRF vulnerability in Dell PowerProtect DD allows remote attackers with high privileges to make the server send requests to internal systems, potentially exposing sensitive information. It affect...

CVE-2025-46643

LOW CVSS 2.3 Jan 9, 2026

A heap-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows high-privileged attackers with local access to cause denial of service. Affected systems include Data Doma...

CVE-2025-46676

LOW CVSS 2.7 Jan 9, 2026

Dell PowerProtect Data Domain systems running affected DD OS versions contain an information disclosure vulnerability. A high-privileged attacker with remote access could exploit this to access sensit...