CVE-2025-43909
CVE-2025-43909
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 3.7EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
07 oct 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Use of a Broken or Risky Cryptographic Algorithm vulnerability in the DD boost. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Dell · PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2023Dell · PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2024Dell · PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS2025Dell · PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →