CVE-2025-46644
Estado: AnalizadaMedia (6.7)—
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.56%
- Percentil entre todas las CVEs puntuadas: 45
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-46644",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-46644",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-01-10T04:55:54.679179Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 0.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) Feature Release",
"versions": [
{
"status": "affected",
"version": "7.7.1.0",
"lessThan": "8.5.0.0",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS 2025",
"versions": [
{
"status": "affected",
"version": "8.3.1.0",
"lessThan": "8.3.1.20",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024",
"versions": [
{
"status": "affected",
"version": "7.13.1.0",
"lessThan": "7.13.1.50",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Dell",
"product": "PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023",
"versions": [
{
"status": "affected",
"version": "7.10.1.0",
"lessThan": "7.10.1.80",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-09T16:16:06.610",
"references": [
{
"url": "https://www.dell.com/support/kbdoc/en-us/000405813/dsa-2025-415-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities",
"tags": [
"Vendor Advisory"
],
"source": "security_alert@emc.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution."
},
{
"lang": "es",
"value": "Dell PowerProtect Data Domain con Data Domain Operating System (DD OS) de las versiones de Feature Release 7.7.1.0 a 8.4.0.0, la versión LTS2025 8.3.1.10, las versiones LTS2024 7.13.1.0 a 7.13.1.40, las versiones LTS2023 7.10.1.0 a 7.10.1.70, contienen una vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando del Sistema Operativo ('Inyección de Comandos del SO'). Un atacante con altos privilegios y acceso local podría potencialmente explotar esta vulnerabilidad, lo que llevaría a la ejecución de comandos."
}
],
"lastModified": "2026-06-17T09:26:45.963",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18AD8BC6-ABF7-4990-91C6-D228BBE4B9FE",
"versionEndExcluding": "7.10.1.80",
"versionStartIncluding": "7.7.1.0"
},
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00F138B9-4AB9-4B79-BBEC-F5A48E2E0B05",
"versionEndExcluding": "7.13.1.50",
"versionStartIncluding": "7.13.1.0"
},
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B8DA06B-076A-495E-9BD0-246BF1E54E26",
"versionEndExcluding": "8.3.1.20",
"versionStartIncluding": "8.3.1.0"
},
{
"criteria": "cpe:2.3:o:dell:data_domain_operating_system:8.4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF73C39B-827B-4A68-9708-08345F6EF979"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}