Dell
Dell Powerprotect Data Manager: vulnerabilidades y CVE
Dell Powerprotect Data Manager tiene 31 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses15
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-74769 | Media (6.5) | 0.41% | — | 3 sept 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to… |
| CVE-2026-74768 | Media (4.1) | 0.36% | — | 3 sept 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability,… |
| CVE-2026-73600 | Alta (7.8) | 0.20% | — | 3 sept 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability,… |
| CVE-2026-68860 | Media (6.8) | 0.38% | — | 3 sept 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of… |
| CVE-2026-49499 | Alta (8.8) | 0.42% | — | 22 jul 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this… |
| CVE-2026-46738 | Alta (7.2) | 0.50% | — | 22 jul 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this… |
| CVE-2026-46737 | Alta (7.2) | 0.63% | — | 22 jul 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this… |
| CVE-2026-44276 | Media (4.4) | 0.15% | — | 22 jul 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could… |
| CVE-2026-40714 | Alta (7.2) | 0.50% | — | 22 jul 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… |
| CVE-2026-40712 | Alta (7.2) | 0.50% | — | 22 jul 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this… |
| CVE-2026-28264 | Media (5.5) | 0.13% | — | 8 abr 2026 | Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this… |
| CVE-2026-22268 | Media (6.5) | 0.20% | — | 19 feb 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading… |
| CVE-2026-22267 | Alta (8.8) | 0.42% | — | 19 feb 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading… |
| CVE-2026-22266 | Alta (8.8) | 0.29% | — | 19 feb 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could… |
| CVE-2026-22269 | Media (4.7) | 0.18% | — | 19 feb 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could… |
| CVE-2025-43938 | Media (4.4) | 0.11% | — | 10 sept 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability,… |
| CVE-2025-43888 | Alta (7.8) | 0.15% | — | 10 sept 2025 | Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit… |
| CVE-2025-43887 | Alta (7.8) | 0.10% | — | 10 sept 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,… |
| CVE-2025-43886 | Media (4.4) | 0.16% | — | 10 sept 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability,… |
| CVE-2025-43885 | Alta (7.8) | 0.53% | — | 10 sept 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with… |
| CVE-2025-43884 | Media (6.7) | 0.46% | — | 10 sept 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with… |
| CVE-2025-43725 | Alta (7.8) | 0.13% | — | 10 sept 2025 | Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit… |
| CVE-2025-30480 | Media (6.5) | 0.35% | — | 30 jul 2025 | Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager. A low privileged attacker with remote access could potentially exploit this… |
| CVE-2025-23377 | Baja (3.4) | 0.15% | — | 28 abr 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this… |
| CVE-2025-23376 | Media (4.4) | 0.17% | — | 28 abr 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access… |
| CVE-2025-23375 | Alta (7.8) | 0.14% | — | 28 abr 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading… |
| CVE-2024-25971 | Media (6.5) | 0.56% | — | 28 mar 2024 | Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure,… |
| CVE-2024-22454 | Alta (8.8) | 0.56% | — | 13 feb 2024 | Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability,… |
| CVE-2024-22445 | Alta (7.2) | 1.4% | — | 13 feb 2024 | Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the execution… |
| CVE-2023-28062 | Alta (8.8) | 0.77% | — | 11 abr 2023 | Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Dell
Secure Connect Gateway · 135Data Domain Operating System · 99Powerscale Onefs · 98EMC Powerscale Onefs · 84Wyse Management Suite · 70Latitude 9410 Firmware · 65Latitude 5411 Firmware · 64Latitude 5511 Firmware · 64Latitude 7410 Firmware · 63Latitude 7310 Firmware · 63Latitude 5310 Firmware · 62Latitude 5400 Firmware · 62