CVE-2025-36568
7.8Dell · PowerProtect Data Domain BoostFS
Dell PowerProtect Data Domain BoostFS contains an insufficiently protected credentials vulnerability that may allow a local attacker to expose sensitive information.
Executive summary
A vulnerability in Dell PowerProtect Data Domain BoostFS allows a low privileged local attacker to potentially gain unauthorized access to credentials and escalate privileges.
Vulnerability
This flaw involves insufficiently protected credentials (CWE-522) within the BoostFS client. A locally authenticated user with low privileges can exploit this to access sensitive credentials, potentially leading to unauthorized system access.
Business impact
The compromise of credentials within a backup infrastructure component poses a significant risk to data confidentiality and integrity. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as successful exploitation could allow an attacker to gain elevated access to the backup system, potentially resulting in unauthorized data modification or exfiltration.
Remediation
Immediate Action: Update the affected Dell PowerProtect Data Domain BoostFS software to the versions specified in the vendor advisory (8.6.0.0, 8.3.1.30, or 7.13.1.60 or later).
Proactive Monitoring: Review system access logs for suspicious activity or unauthorized attempts to access credential stores and sensitive configuration files.
Compensating Controls: Ensure strict adherence to the principle of least privilege by restricting local account access on systems where BoostFS is installed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize applying the provided vendor patches to their PowerProtect Data Domain BoostFS environments to remediate this credential exposure risk. Given that the vulnerability allows for privilege escalation via credential theft, failure to patch leaves backup infrastructure susceptible to internal threats and lateral movement.