CVE-2025-36594
critical · 9.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.
9.8
CVSS
0.5%
EPSS (exploit prob.)
41st
EPSS percentile
2025-08-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-290
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| dell | data_domain_operating_system | >= 7.7.1.0, < 7.10.1.70 |
| dell | data_domain_operating_system | >= 7.13.1.0, < 7.13.1.30 |
| dell | data_domain_operating_system | >= 8.0.0.0, < 8.3.1.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-36594