« Volver al listado

CVE-2025-30096

Estado: AnalizadaMedia (6.7)—

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-30096",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-30096",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-12T03:55:19.668678Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "PowerProtect Data Domain Feature Release",
          "versions": [
            {
              "status": "affected",
              "version": "7.7.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.1.0.10"
            }
          ],
          "packageName": "Feature Release",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Dell",
          "product": "PowerProtect Data Domain LTS2024",
          "versions": [
            {
              "status": "affected",
              "version": "7.13.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "7.13.1.25"
            }
          ],
          "packageName": "LTS2024",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Dell",
          "product": "PowerProtect Data Domain LTS 2023",
          "versions": [
            {
              "status": "affected",
              "version": "7.10.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "7.10.1.50"
            }
          ],
          "packageName": "LTS 2023",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-04T15:15:31.397",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000348708/dsa-2025-159-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges."
    },
    {
      "lang": "es",
      "value": "Dell PowerProtect Data Domain con el sistema operativo Data Domain (DD OS) de las versiones Feature Release 7.7.1.0 a 8.1.0.10, LTS2024 de la 7.13.1.0 a la 7.13.1.25 y LTS 2023 de la 7.10.1.0 a la 7.10.1.50, presenta una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('inyección de comandos del sistema operativo') en la CLI de DDSH. Un atacante con privilegios elevados y acceso local podría aprovechar esta vulnerabilidad para ejecutar comandos arbitrarios con privilegios de root."
    }
  ],
  "lastModified": "2026-06-17T09:08:09.343",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2389C08-162A-4D43-B1EA-D93D7DB51781",
              "versionEndExcluding": "7.10.1.60",
              "versionStartIncluding": "7.7.1.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72E654A0-AB50-454D-8345-A29F71EA6727",
              "versionEndExcluding": "7.13.1.30",
              "versionStartIncluding": "7.11.0.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD518568-542A-420D-B0E6-6F35E127E5CE",
              "versionEndExcluding": "8.3.0.10",
              "versionStartIncluding": "8.0.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}