PT-2025-37058 · Dell · Dell Powerprotect Data Manager

Published

2025-04-18

·

Updated

2025-09-17

·

CVE-2025-43884

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell PowerProtect Data Manager versions 19.19 and 19.20
Description: Dell PowerProtect Data Manager, running on Hyper-V, contains an Improper Neutralization of Special Elements used in an OS Command vulnerability, potentially allowing a high-privileged attacker with local access to execute commands.
Recommendations: Update Dell PowerProtect Data Manager to a version that addresses this issue.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-11422
CVE-2025-43884

Affected Products

Dell Powerprotect Data Manager