# CVE-2025-29987

## Summary

- **CVE ID:** CVE-2025-29987
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-1220
- **Published:** Apr 3, 2025
- **Last Modified:** Mar 13, 2026

## Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.

## Affected Products

- Dell — DD OS 8.3 (7.7.1.0)
- Dell — DD OS 7.13 (7.13.1.0)
- Dell — DD OS 7.10 (7.10.1.0)
- Dell — PowerProtect DP Series Appliance (IDPA) (N/A)

## References

- [CNA](https://www.dell.com/support/kbdoc/en-us/000300899/dsa-2025-139-dell-technologies-powerprotect-data-domain-security-update-for-a-security-vulnerability)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.53%
- **EPSS Percentile:** 42.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._