Dell PowerProtect DDOS 8.4-8.5 Session Fixation Vulnerability
CVE-2025-46605 Published on April 17, 2026
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
Vulnerability Analysis
CVE-2025-46605 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Affected Versions
Dell PowerProtect Data Domain:- Before 8.6.0.0 or later is affected.