PT-2025-18078 · Dell · Dell Powerprotect Data Manager Reporting

Published

2025-04-24

·

Updated

2025-05-13

·

CVE-2025-23375

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Manager Reporting version 19.17
Description The issue is related to an incorrect use of privileged APIs, which could be exploited by an attacker with low privileges and local access, potentially leading to elevation of privileges.
Recommendations For Dell PowerProtect Data Manager Reporting version 19.17, consider restricting local access to minimize the risk of exploitation until a fix is available. As a temporary workaround, consider disabling any functionality that relies on privileged APIs until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-05375
CVE-2025-23375

Affected Products

Dell Powerprotect Data Manager Reporting