CVE-2024-53295 Details
Description
Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.
A vulnerability has been identified in Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20. This vulnerability involves improper access control, which could be exploited by a local user with low privileges to escalate privileges on the system.
Users can upgrade to Dell PowerProtect DD version 8.3.0.0 or later, or version 7.13.1.20 or later. For version 7.10, users should upgrade to version 7.10.1.50 or later. Instructions for downloading the update are available on the Dell Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dell.com/support/kbdoc/en-us/000279157/dsa-2025-022-security-update-for-dell-powerprotect-dd-multiple-vulnerabilities | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-1220 | Insufficient Granularity of Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell data domain operating system | >= 7.10.1.0, < 7.10.1.50 >= 7.13.1.0, < 7.13.1.20 >= 7.14.0.0, < 8.3.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 7, 2025 | Initial Analysis | [email protected] |
| Feb 1, 2025 | New CVE Received | [email protected] |