CVE-2024-37138: Dell Data Domain Operating System

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized file to the managed system.

Affected products

  • Dell Data Domain Operating System: before 7.7.5.40 (fixed in 7.7.5.40); from 7.8.0.0, before 7.10.1.30 (fixed in 7.10.1.30); from 7.11.0.0, before 7.13.1.0 (fixed in 7.13.1.0)

Published 2024-06-26. Last modified 2026-06-17.