CVE-2025-43914

7.5

Dell · PowerProtect Data Domain BoostFS

Dell PowerProtect Data Domain BoostFS for Linux Ubuntu contains an incorrect privilege assignment vulnerability, potentially allowing a local attacker to gain unauthorized access.

Executive summary

A high-severity incorrect privilege assignment vulnerability in Dell PowerProtect Data Domain BoostFS could allow a low-privileged local attacker to gain unauthorized access, posing a significant risk to system integrity.

Vulnerability

The software contains an incorrect privilege assignment vulnerability (CWE-266), which can be exploited by a low-privileged attacker with local access to achieve unauthorized access to the system.

Business impact

Successful exploitation of this flaw could lead to a complete compromise of the affected system, as the vulnerability allows for escalated privileges and unauthorized access. Given the CVSS score of 7.5, this is considered a high-risk issue that could result in the exposure of sensitive backup data or unauthorized administrative control over the storage environment.

Remediation

Immediate Action: Update the affected Dell PowerProtect Data Domain BoostFS software to the versions specified in the vendor security advisory (DSA-2025-333) as soon as possible.

Proactive Monitoring: Review system access logs for suspicious activity, particularly any unexpected privilege escalation attempts or unauthorized execution by local user accounts.

Compensating Controls: Restrict local access to the affected Linux Ubuntu systems to only authorized personnel and ensure that the principle of least privilege is strictly enforced for all local user accounts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk to the integrity of storage management systems. Administrators should prioritize the deployment of the vendor-provided updates immediately to close the privilege escalation vector, as local attackers could otherwise leverage this flaw to gain unauthorized control over the affected infrastructure.

More Dell CVEs

Sources