CVE-2025-43888

8.8

Dell · PowerProtect Data Manager

Dell PowerProtect Data Manager versions 19.19 and 19.20 are vulnerable to the insertion of sensitive information into log files, which may lead to unauthorized access by local attackers.

Executive summary

A vulnerability in Dell PowerProtect Data Manager allows a low privileged local attacker to gain unauthorized access by exploiting sensitive information improperly stored in log files.

Vulnerability

This is an insertion of sensitive information into log files (CWE-532) vulnerability. A low privileged attacker with local access can leverage this flaw to potentially escalate privileges or gain unauthorized access to sensitive system data.

Business impact

The exposure of sensitive information within system logs can lead to a total compromise of confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability represents a high risk to organizational security, as it facilitates unauthorized access to critical backup infrastructure and potentially the data contained within those environments.

Remediation

Immediate Action: Update Dell PowerProtect Data Manager to version 19.21 build 11 or later as specified in the official vendor advisory (DSA-2025-326).

Proactive Monitoring: Audit system logs for unauthorized access attempts or suspicious activity originating from low-privileged local user accounts.

Compensating Controls: Restrict local system access to authorized personnel only and ensure that log files are protected with strict file system permissions to prevent unauthorized viewing of sensitive data.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Dell PowerProtect Data Manager must prioritize the application of the vendor-supplied security update to version 19.21 build 11. Although the requirement for local access somewhat limits the attack surface, the high CVSS severity underscores the danger of allowing sensitive credentials or configuration data to reside in plaintext logs, which could lead to a full system compromise.

More Dell CVEs

Sources