ID

VAR-202508-1700


CVE

CVE-2025-30098


TITLE

Dell's  data domain operating system  In  OS  Command injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2025-016439

DESCRIPTION

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the DDSH CLI. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. (DoS) It may be in a state. Dell PowerProtect Data Domain (Dell PowerProtect DD) is a set of hardware appliances from Dell for data protection, backup, storage, and deduplication

Trust: 2.16

sources: NVD: CVE-2025-30098 // JVNDB: JVNDB-2025-016439 // CNVD: CNVD-2025-22716

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-22716

AFFECTED PRODUCTS

vendor:dellmodel:data domain operating systemscope:gteversion:7.7.1.0

Trust: 1.0

vendor:dellmodel:data domain operating systemscope:ltversion:7.13.1.30

Trust: 1.0

vendor:dellmodel:data domain operating systemscope:gteversion:7.11.0.0

Trust: 1.0

vendor:dellmodel:data domain operating systemscope:gteversion:8.0.0.0

Trust: 1.0

vendor:dellmodel:data domain operating systemscope:ltversion:7.10.1.60

Trust: 1.0

vendor:dellmodel:data domain operating systemscope:ltversion:8.3.0.10

Trust: 1.0

vendor:デルmodel:data domain operating systemscope:eqversion:7.7.1.0 that's all 7.10.1.60

Trust: 0.8

vendor:デルmodel:data domain operating systemscope:eqversion:7.11.0.0 that's all 7.13.1.30

Trust: 0.8

vendor:デルmodel:data domain operating systemscope:eqversion: -

Trust: 0.8

vendor:デルmodel:data domain operating systemscope:eqversion:8.0.0.0 that's all 8.3.0.10

Trust: 0.8

vendor:デルmodel:data domain operating systemscope: - version: -

Trust: 0.8

vendor:dellmodel:powerprotect data domainscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-22716 // JVNDB: JVNDB-2025-016439 // NVD: CVE-2025-30098

CVSS

SEVERITY

CVSSV2

CVSSV3

security_alert@emc.com: CVE-2025-30098
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2025-016439
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2025-22716
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-22716
severity: MEDIUM
baseScore: 6.5
vectorString: AV:L/AC:L/AU:M/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 2.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

security_alert@emc.com: CVE-2025-30098
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-016439
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-22716 // JVNDB: JVNDB-2025-016439 // NVD: CVE-2025-30098

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.0

problemtype:OS Command injection (CWE-78) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-016439 // NVD: CVE-2025-30098

PATCH

title:Patch for Dell PowerProtect Data Domain Operating System Command Injection Vulnerability (CNVD-2025-22716)url:https://www.cnvd.org.cn/patchInfo/show/738276

Trust: 0.6

sources: CNVD: CNVD-2025-22716

EXTERNAL IDS

db:NVDid:CVE-2025-30098

Trust: 3.2

db:JVNDBid:JVNDB-2025-016439

Trust: 0.8

db:CNVDid:CNVD-2025-22716

Trust: 0.6

sources: CNVD: CNVD-2025-22716 // JVNDB: JVNDB-2025-016439 // NVD: CVE-2025-30098

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000348708/dsa-2025-159-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-30098

Trust: 1.4

sources: CNVD: CNVD-2025-22716 // JVNDB: JVNDB-2025-016439 // NVD: CVE-2025-30098

SOURCES

db:CNVDid:CNVD-2025-22716
db:JVNDBid:JVNDB-2025-016439
db:NVDid:CVE-2025-30098

LAST UPDATE DATE

2025-11-22T23:34:21.439000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-22716date:2025-09-28T00:00:00
db:JVNDBid:JVNDB-2025-016439date:2025-10-20T06:09:00
db:NVDid:CVE-2025-30098date:2025-10-16T14:41:47.683

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-22716date:2025-09-28T00:00:00
db:JVNDBid:JVNDB-2025-016439date:2025-10-20T00:00:00
db:NVDid:CVE-2025-30098date:2025-08-04T15:15:31.723