CVE Vulnerabilities

CVE-2025-43727

Incorrect Implementation of Authentication Algorithm

Published: Oct 07, 2025 | Modified: Oct 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an incorrect Implementation of Authentication Algorithm vulnerability in the RestAPI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

Name Vendor Start Version End Version
Data_domain_operating_system Dell 7.7.1.0 (including) 7.10.1.60 (excluding)
Data_domain_operating_system Dell 7.13.1.0 (including) 7.13.1.30 (excluding)
Data_domain_operating_system Dell 8.0.0.0 (including) 8.3.0.10 (excluding)

References