CVE-2025-43938

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to gain unauthorized access with privileges of the compromised account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:*

History

20 Oct 2025, 14:02

Type Values Removed Values Added
CPE cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:*
First Time Dell
Dell powerprotect Data Manager
References () https://www.dell.com/support/kbdoc/en-us/000367456/dsa-2025-326-security-update-for-dell-powerprotect-data-manager-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000367456/dsa-2025-326-security-update-for-dell-powerprotect-data-manager-multiple-security-vulnerabilities - Vendor Advisory

10 Sep 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-10 16:15

Updated : 2025-10-20 14:02


NVD link : CVE-2025-43938

Mitre link : CVE-2025-43938

CVE.ORG link : CVE-2025-43938


JSON object : View

Products Affected

dell

  • powerprotect_data_manager
CWE
CWE-256

Unprotected Storage of Credentials