CVE-2025-36568

7.8

Dell · PowerProtect Data Domain BoostFS

Dell PowerProtect Data Domain BoostFS contains an insufficiently protected credentials vulnerability that may allow a local attacker to expose sensitive information.

Executive summary

A vulnerability in Dell PowerProtect Data Domain BoostFS allows a low privileged local attacker to potentially gain unauthorized access to credentials and escalate privileges.

Vulnerability

This flaw involves insufficiently protected credentials (CWE-522) within the BoostFS client. A locally authenticated user with low privileges can exploit this to access sensitive credentials, potentially leading to unauthorized system access.

Business impact

The compromise of credentials within a backup infrastructure component poses a significant risk to data confidentiality and integrity. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as successful exploitation could allow an attacker to gain elevated access to the backup system, potentially resulting in unauthorized data modification or exfiltration.

Remediation

Immediate Action: Update the affected Dell PowerProtect Data Domain BoostFS software to the versions specified in the vendor advisory (8.6.0.0, 8.3.1.30, or 7.13.1.60 or later).

Proactive Monitoring: Review system access logs for suspicious activity or unauthorized attempts to access credential stores and sensitive configuration files.

Compensating Controls: Ensure strict adherence to the principle of least privilege by restricting local account access on systems where BoostFS is installed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize applying the provided vendor patches to their PowerProtect Data Domain BoostFS environments to remediate this credential exposure risk. Given that the vulnerability allows for privilege escalation via credential theft, failure to patch leaves backup infrastructure susceptible to internal threats and lateral movement.

More Dell CVEs

Sources