Dell has released a Critical Security Update (DSA-2025-022) for its PowerProtect Data Domain (DD) systems to address multiple vulnerabilities that could allow attackers to compromise affected systems.
These vulnerabilities, identified in various components and open-source dependencies, highlight the importance of timely patching to safeguard enterprise data protection environments.
The vulnerabilities include seven classified as “Critical” severity—CVE-2024-33871, CVE-2024-41110, CVE-2024-38428, CVE-2024-24790, CVE-2024-37371, CVE-2024-24577, and CVE-2018-6913—which may allow escalation of privileges, unauthorized system access, denial of service, or sensitive data exfiltration.
Breakdown of Critical CVEs
Affected Products
The vulnerabilities impact multiple Dell PowerProtect DD systems. Organizations using these systems are urged to review Dell’s official advisory (DSA-2025-022) to identify specific affected models and implement the recommended patches.
Dell has released security patches to address these vulnerabilities. Administrators are advised to:
The discovery of critical vulnerabilities in enterprise backup and recovery products like Dell PowerProtect DD underscores the need for constant vigilance and timely patch management.
Organizations relying on these systems must act swiftly to mitigate risks and ensure data security.
Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN Sandox -> Start Now for Free.
Microsoft Threat Intelligence has exposed a novel cyberattack method employed by the North Korean state-sponsored…
Microsoft has confirmed the discovery of a significant zero-day vulnerability, tracked as CVE-2025-21418, in the Windows…
A critical vulnerability in Fortinet's FortiOS and FortiProxy products has been identified, enabling attackers to…
Fortinet’s FortiOS, the operating system powering its VPN and firewall appliances, has been found vulnerable…
A newly discovered 0-day vulnerability in Windows Storage has sent shockwaves through the cybersecurity community.…
A newly discovered malware, dubbed "Ratatouille" (or I2PRAT), is raising alarms in the cybersecurity community…