CVE-2025-43725
7.8Dell · PowerProtect Data Manager
Dell PowerProtect Data Manager contains an incorrect default permissions vulnerability in the Generic Application Agent, allowing local attackers to achieve code execution.
Executive summary
A high-severity incorrect default permissions vulnerability in Dell PowerProtect Data Manager could allow a low-privileged local attacker to gain unauthorized code execution.
Vulnerability
The Generic Application Agent exhibits an incorrect default permissions flaw (CWE-276), which can be exploited by an authenticated local attacker with low privileges to execute arbitrary code on the underlying system.
Business impact
Successful exploitation of this vulnerability poses a significant risk to the integrity and availability of the affected backup management infrastructure. By achieving code execution, an attacker could potentially compromise sensitive backup data, disable security controls, or move laterally within the network, justifying the high CVSS score of 7.8.
Remediation
Immediate Action: Update the Dell PowerProtect Data Manager Generic Application Agent to version 19.21 build 11 or later to resolve the permission flaw.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unauthorized modifications to sensitive configuration files within the agent directory.
Compensating Controls: Restrict local system access to the server hosting the Generic Application Agent to authorized administrators only to prevent low-privileged users from interacting with the vulnerable component.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for code execution on critical backup infrastructure, organizations should prioritize the deployment of the vendor-supplied patch. Administrators must verify their current version of the Generic Application Agent and ensure the update to version 19.21 build 11 is applied immediately to eliminate this security risk.