HomeCVE-2025-46644

CVE-2025-46644

MEDIUM
6.0CVSS
Published: 2026-01-09
Updated: 2026-01-13
AI Analysis

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
high
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
high
Availability
high
Weaknesses
CWE-78

Metadata

Primary Vendor
UNKNOWN
Published
1/9/2026
Last Modified
1/13/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

No affected products information available.

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief