PT-2025-37069 · Dell · Dell Powerprotect Data Manager

Published

2025-04-18

·

Updated

2025-10-20

·

CVE-2025-43886

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Dell PowerProtect Data Manager versions 19.19 and 19.20
Description: Dell PowerProtect Data Manager versions 19.19 and 19.20, when used with Hyper-V, contain a path traversal vulnerability. A high-privileged attacker with local access could potentially exploit this vulnerability to gain filesystem access. The vulnerability involves the use of a '.../...//' path traversal sequence.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-11423
CVE-2025-43886

Affected Products

Dell Powerprotect Data Manager