Incorrect Privilege Assignment in Dell PowerProtect Data Domain for Linux Ubuntu
CVE-2025-43914

7.5HIGH

What is CVE-2025-43914?

The vulnerability in Dell PowerProtect Data Domain BoostFS for Ubuntu systems arises from an Incorrect Privilege Assignment, where a low privileged attacker with local access can exploit this flaw to gain unauthorized access to sensitive data or functionalities. This exposure highlights the need for timely updates and patches to mitigate the risk of unauthorized actions within vulnerable systems.

Affected Version(s)

PowerProtect Data Domain BoostFS for Linux Ubuntu Feature Release 7.7.1.0 < 8.4.0.0

PowerProtect Data Domain BoostFS for Linux Ubuntu LTS2023 7.10.1.0 < 7.10.1.70

PowerProtect Data Domain BoostFS for Linux Ubuntu LTS2024 7.13.1.0 < 7.13.1.40

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.