Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    16 Oct 2025, 14:39
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:* | |
| First Time | 
        
        Dell
         Dell data Domain Operating System  | 
|
| References | () https://www.dell.com/support/kbdoc/en-us/000348708/dsa-2025-159-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities - Vendor Advisory | 
05 Aug 2025, 14:34
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
04 Aug 2025, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-04 15:15
Updated : 2025-10-16 14:39
NVD link : CVE-2025-36594
Mitre link : CVE-2025-36594
CVE.ORG link : CVE-2025-36594
JSON object : View
Products Affected
                dell
- data_domain_operating_system
 
CWE
                
                    
                        
                        CWE-290
                        
            Authentication Bypass by Spoofing
