CNNVD-202508-219 Information

CNNVD ID

CNNVD-202508-219

CVE-2025-30098

  • CNNVD Published: 2025-08-04

Description (Chinese)

Dell PowerProtect Data Domain(Dell PowerProtect DD)是美国戴尔(Dell)公司的一套用于数据保护、备份、存储和重复数据消除的硬件设备。 Dell PowerProtect Data Domain存在操作系统命令注入漏洞,该漏洞源于OS命令注入,可能导致执行任意命令。以下版本受到影响:7.7.1.0至8.1.0.10版本、7.13.1.0至7.13.1.25版本和7.10.1.0至7.10.1.50版本。

Description (English)

Dell PowerProtec Data Domain (Dell PowerProtec DD) is a set of hardware equipment for data protection, backup, storage and duplicate data elimination from Dell, United States. Dell PowerProtec Data Domain has an operational system command to inject a loophole, which originates from an OS order and may lead to the execution of an arbitrary order. The following versions are affected: Versions 7.7.1.0 to 8.1.010, Versions 7.13.1.0 to 7.1.125 and Versions 7.10.1.0 to 7.10.1.50.

Hazard Level

High

Vulnerability Type

操作系统命令注入

Affected Vendor

戴尔

Published

2025-08-04

Last Modified

2026-02-24

References

https://www.dell.com/support/kbdoc/en-us/000348708/dsa-2025-159-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities

Patch

https://www.dell.com/support/kbdoc/en-us/000348708/dsa-2025-159-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities

Share on: