Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.
CVE ID: CVE-2025-29987
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: Dell, Dell, Dell, Dell
Product: DD OS 8.3, DD OS 7.13, DD OS 7.10, PowerProtect DP Series Appliance (IDPA)
EPSS Score: 0.07% (probability of being exploited)
EPSS Percentile: 21.35% (scored less or equal to compared to others)
EPSS Date: 2025-05-02 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: false