CVE-2025-46643
Estado: AnalizadaMedia (4.4)—
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-122
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-46643",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-46643",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-01-09T17:48:48.190298Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) Feature Release",
"versions": [
{
"status": "affected",
"version": "7.7.1.0",
"lessThan": "8.5.0.0",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025",
"versions": [
{
"status": "affected",
"version": "8.3.1.0",
"lessThan": "8.3.1.20",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024",
"versions": [
{
"status": "affected",
"version": "7.13.1.0",
"lessThan": "7.13.1.50",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023",
"versions": [
{
"status": "affected",
"version": "7.10.1.0",
"lessThan": "7.10.1.80",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-09T16:16:06.443",
"references": [
{
"url": "https://www.dell.com/support/kbdoc/en-us/000405813/dsa-2025-415-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
"tags": [
"Vendor Advisory"
],
"source": "security_alert@emc.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"description": [
{
"lang": "en",
"value": "CWE-122"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service."
},
{
"lang": "es",
"value": "Dell PowerProtect Data Domain con el sistema operativo Data Domain (DD OS) de las versiones Feature Release 7.7.1.0 a 8.4.0.0, la versión LTS2025 8.3.1.10, las versiones LTS2024 7.13.1.0 a 7.13.1.40, y las versiones LTS 2023 7.10.1.0 a 7.10.1.70, contienen una vulnerabilidad de desbordamiento de búfer basado en montículo. Un atacante con altos privilegios y acceso local podría potencialmente explotar esta vulnerabilidad, lo que llevaría a una denegación de servicio."
}
],
"lastModified": "2026-06-17T09:26:45.850",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18AD8BC6-ABF7-4990-91C6-D228BBE4B9FE",
"versionEndExcluding": "7.10.1.80",
"versionStartIncluding": "7.7.1.0"
},
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00F138B9-4AB9-4B79-BBEC-F5A48E2E0B05",
"versionEndExcluding": "7.13.1.50",
"versionStartIncluding": "7.13.1.0"
},
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B8DA06B-076A-495E-9BD0-246BF1E54E26",
"versionEndExcluding": "8.3.1.20",
"versionStartIncluding": "8.3.1.0"
},
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:8.4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF73C39B-827B-4A68-9708-08345F6EF979"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}