OS Command Injection Vulnerability in Dell PowerProtect Data Manager
CVE-2025-43885
7.8HIGH
What is CVE-2025-43885?
The Dell PowerProtect Data Manager, specifically versions 19.19 and 19.20, has a vulnerability that arises from improper neutralization of special elements utilized in OS commands. This weakness can be exploited by a low privileged attacker with local access, allowing them to execute arbitrary commands on the affected system. Organizations using these versions should be aware of potential risks and implement necessary security measures.
Affected Version(s)
PowerProtect Data Manager < 19.21 build 11
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved