OS Command Injection Vulnerability in Dell PowerProtect Data Manager
CVE-2025-43885

7.8HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
10 September 2025

What is CVE-2025-43885?

The Dell PowerProtect Data Manager, specifically versions 19.19 and 19.20, has a vulnerability that arises from improper neutralization of special elements utilized in OS commands. This weakness can be exploited by a low privileged attacker with local access, allowing them to execute arbitrary commands on the affected system. Organizations using these versions should be aware of potential risks and implement necessary security measures.

Affected Version(s)

PowerProtect Data Manager < 19.21 build 11

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.