{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-43914","assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","state":"PUBLISHED","assignerShortName":"dell","dateReserved":"2025-04-19T05:03:41.170Z","datePublished":"2025-10-07T17:43:48.551Z","dateUpdated":"2026-02-26T17:48:15.108Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"PowerProtect Data Domain BoostFS for Linux Ubuntu Feature Release","vendor":"Dell","versions":[{"lessThan":"8.4.0.0","status":"affected","version":"7.7.1.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PowerProtect Data Domain BoostFS for Linux Ubuntu LTS2025","vendor":"Dell","versions":[{"lessThan":"8.3.1.10","status":"affected","version":"8.3.1.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PowerProtect Data Domain BoostFS for Linux Ubuntu LTS2024","vendor":"Dell","versions":[{"lessThan":"7.13.1.40","status":"affected","version":"7.13.1.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"PowerProtect Data Domain BoostFS for Linux Ubuntu LTS2023","vendor":"Dell","versions":[{"lessThan":"7.10.1.70","status":"affected","version":"7.10.1.0","versionType":"semver"}]}],"datePublic":"2025-10-01T17:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access."}],"value":"Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-266","description":"CWE-266: Incorrect Privilege Assignment","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell","dateUpdated":"2025-10-07T17:43:48.551Z"},"references":[{"tags":["vendor-advisory"],"url":"https://www.dell.com/support/kbdoc/en-us/000376224/dsa-2025-333-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-43914","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-10-08T03:55:18.919586Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T17:48:15.108Z"}}]}}