DSA-2025-415: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities
概要: Dell PowerProtect Data Domain remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
この記事は次に適用されます:
この記事は次には適用されません:
この記事は、特定の製品に関連付けられていません。
すべての製品パージョンがこの記事に記載されているわけではありません。
影響
Critical
詳細情報
Critical severity originates from CVE-2024-38476 associated with Apache component
詳細
|
Third-Party Component
|
CVEs
|
More Information
|
| Apache server |
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709
|
https://nvd.nist.gov/vuln/search |
| Apache Tomcat |
CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125
|
https://nvd.nist.gov/vuln/search |
|
Libexpat
|
CVE-2024-8176
|
https://nvd.nist.gov/vuln/search |
| Jinja |
CVE-2025-27516
|
https://nvd.nist.gov/vuln/search |
| CPython |
CVE-2025-0938
|
https://nvd.nist.gov/vuln/search |
|
Proprietary Code CVEs
|
Description
|
CVSS Base Score
|
CVSS Vector String
|
| CVE-2025-46645 |
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
|
6.5
|
|
|
CVE-2025-46644
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
|
6.0
|
|
|
CVE-2025-46676
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
|
2.7
|
|
| CVE-2025-46643 |
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
|
2.3
|
|
Proprietary Code CVEs
|
Description
|
CVSS Base Score
|
CVSS Vector String
|
| CVE-2025-46645 |
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
|
6.5
|
|
|
CVE-2025-46644
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
|
6.0
|
|
|
CVE-2025-46676
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
|
2.7
|
|
| CVE-2025-46643 |
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
|
2.3
|
影響を受ける製品と修復
|
CVEs Addressed
|
Product
|
Software/Firmware
|
Affected Versions
|
Remediated Versions
|
Link
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 8.5 |
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) Feature Release
|
Versions 7.7.1.0 through 8.4.0.0
|
Version 8.5.0.0 or later
|
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 8.3.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2025 8.3.1
|
Versions 8.3.1.0 through 8.3.1.10
|
Version 8.3.1.20 or later
|
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 7.13.1 |
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2024 7.13.1
|
Versions 7.13.1.0 through 7.13.1.40
|
Version 7.13.1.50 or later
|
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 7.10.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2023 7.10.1
|
Versions 7.10.1.0 through 7.10.1.70
|
Version 7.10.1.80 or later
|
|
|
CVE-2025-27516, CVE-2025-0938, CVE-2025-46644, CVE-2025-46643
|
DD OS 8.5
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) Feature Release
|
Versions 7.7.1.0 through 8.4.0.0
|
Version 8.5.0.0 or later
|
|
|
CVE-2025-27516, CVE-2025-46644, CVE-2025-46643
|
DD OS 8.3.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2025 8.3.1
|
Versions 8.3.1.0 through 8.3.1.10
|
Version 8.3.1.20 or later
|
|
|
CVE-2025-27516, CVE-2025-0938, CVE-2025-46644, CVE-2025-46643
|
DD OS 7.13.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2024 7.13.1
|
Versions 7.13.1.0 through 7.13.1.40
|
Version 7.13.1.50 or later
|
|
|
CVE-2025-27516, CVE-2025-46644, CVE-2025-46643
|
DD OS 7.10.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2023 7.10.1
|
Versions 7.10.1.0 through 7.10.1.70
|
Version 7.10.1.80 or later
|
|
|
CVE-2024-8176
|
DD OS 8.5 |
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release
|
Versions 7.7.1.0 through 8.4.0.0
|
Version 8.5.0.0 or later
|
|
|
CVE-2024-8176
|
DD OS 8.3.1 |
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release LTS2025 8.3.1
|
Versions 8.3.1.0 through 8.3.1.10
|
Version 8.3.1.20 or later
|
|
|
CVE-2024-8176
|
DD OS 7.13.1
|
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release LTS2024 7.13.1
|
Versions 7.13.1.0 through 7.13.1.40
|
Version 7.13.1.50 or later
|
|
|
CVE-2024-8176
|
DD OS 7.10.1
|
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release LTS2023 7.10.1
|
Versions 7.10.1.0 through 7.10.1.70
|
Version 7.10.1.80 or later
|
|
CVEs Addressed
|
Product
|
Software/Firmware
|
Affected Versions
|
Remediated Versions
|
Link
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 8.5 |
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) Feature Release
|
Versions 7.7.1.0 through 8.4.0.0
|
Version 8.5.0.0 or later
|
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 8.3.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2025 8.3.1
|
Versions 8.3.1.0 through 8.3.1.10
|
Version 8.3.1.20 or later
|
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 7.13.1 |
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2024 7.13.1
|
Versions 7.13.1.0 through 7.13.1.40
|
Version 7.13.1.50 or later
|
|
|
CVE-2024-38476, CVE-2024-38477, CVE-2023-38709, CVE-2025-48734, CVE-2025-48976, CVE-2025-48988, CVE-2025-49124, CVE-2025-49125, CVE-2025-46645, CVE-2025-46676
|
DD OS 7.10.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, Data Domain Management Center, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2023 7.10.1
|
Versions 7.10.1.0 through 7.10.1.70
|
Version 7.10.1.80 or later
|
|
|
CVE-2025-27516, CVE-2025-0938, CVE-2025-46644, CVE-2025-46643
|
DD OS 8.5
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) Feature Release
|
Versions 7.7.1.0 through 8.4.0.0
|
Version 8.5.0.0 or later
|
|
|
CVE-2025-27516, CVE-2025-46644, CVE-2025-46643
|
DD OS 8.3.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2025 8.3.1
|
Versions 8.3.1.0 through 8.3.1.10
|
Version 8.3.1.20 or later
|
|
|
CVE-2025-27516, CVE-2025-0938, CVE-2025-46644, CVE-2025-46643
|
DD OS 7.13.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2024 7.13.1
|
Versions 7.13.1.0 through 7.13.1.40
|
Version 7.13.1.50 or later
|
|
|
CVE-2025-27516, CVE-2025-46644, CVE-2025-46643
|
DD OS 7.10.1
|
Dell PowerProtect Data Domain series appliances, Data Domain Virtual Edition, and Dell APEX Protection Storage with Data Domain Operating System (DD OS) LTS2023 7.10.1
|
Versions 7.10.1.0 through 7.10.1.70
|
Version 7.10.1.80 or later
|
|
|
CVE-2024-8176
|
DD OS 8.5 |
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release
|
Versions 7.7.1.0 through 8.4.0.0
|
Version 8.5.0.0 or later
|
|
|
CVE-2024-8176
|
DD OS 8.3.1 |
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release LTS2025 8.3.1
|
Versions 8.3.1.0 through 8.3.1.10
|
Version 8.3.1.20 or later
|
|
|
CVE-2024-8176
|
DD OS 7.13.1
|
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release LTS2024 7.13.1
|
Versions 7.13.1.0 through 7.13.1.40
|
Version 7.13.1.50 or later
|
|
|
CVE-2024-8176
|
DD OS 7.10.1
|
Dell PowerProtect Data Domain Management Center with Data Domain Operating System (DD OS) Feature Release LTS2023 7.10.1
|
Versions 7.10.1.0 through 7.10.1.70
|
Version 7.10.1.80 or later
|
- PowerProtect Data Domain: Software Versions : This KB article provides the status of the current active PowerProtect Data Domain Operating System (DD OS) releases, along with links to the release notes. (Requires support.dell.com login to view article).
- For instructions on how to upgrade Data Domain Operating System (DD OS), see Data Domain and DDVE: How to Upgrade the Data Domain Operating System
- Some security scanners may still report False Positive findings after upgrading to remediated DDOS versions. For more details, please refer to the respective False Positive KB articles:
-
- Dell PowerProtect Data Domain False Positive Security Vulnerabilities for DD OS 8.5
- Dell PowerProtect Data Domain False Positive Security Vulnerabilities for DDOS 8.3
- Dell Data Domain False Positive Security Vulnerabilities for DDOS 7.13
- Dell Data Domain False Positive Security Vulnerabilities for DDOS 7.10
変更履歴
|
Revision
|
Date
|
Description
|
|
1.0
|
2025-19-12
|
Initial Release
|
|
2.0
|
2025-22-12
|
Minor Update: typo in the title was corrected
|
|
3.0
|
2026-05-01
|
Updated for enhanced presentation with no changes to content
|
関連情報
法的免責事項
対象製品
DD3300 Appliance, Data Domain Deduplication Storage Systems, Data Domain Virtual Edition, DD6300 Appliance, DD6400 Appliance, DD6410 Appliance, DD6900 Appliance, DD9400 Appliance, DD9410 Appliance, DD9900 Appliance, DD9910 Appliance
, DD9910F Appliance
...
文書のプロパティ
文書番号: 000405813
文書の種類: Dell Security Advisory
最終更新: 05 1月 2026
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。