PT-2025-37070 · Dell · Dell Powerprotect Data Manager

Published

2025-04-18

·

Updated

2025-10-20

·

CVE-2025-43887

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell PowerProtect Data Manager versions 19.19 and 19.20
Description: Dell PowerProtect Data Manager, running on Hyper-V, contains an Incorrect Default Permissions issue. A low-privileged attacker with local access could potentially exploit this issue, leading to Elevation of privileges.
Recommendations: For Dell PowerProtect Data Manager version 19.19, apply appropriate permission restrictions. For Dell PowerProtect Data Manager version 19.20, apply appropriate permission restrictions.

Fix

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2025-11420
CVE-2025-43887

Affected Products

Dell Powerprotect Data Manager