CVE-2025-43938
Dell Powerprotect Data Manager ≤ 19.21
Raw vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:NSummary
CVE-2025-43938 is a medium-severity Plaintext Storage of a Password (CWE-256) vulnerability in Dell Powerprotect Data Manager. Its CVSS base score is 5.0 (Medium).
Operationally, ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-5 (Authenticator Management) and SC-28 (Protection of Information at Rest) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-27576
Vulnerability Data
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may…
more
be able to use the exposed credentials to gain unauthorized access with privileges of the compromised account.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires cryptographic or equivalent protection of sensitive data (passwords) at rest, eliminating the plaintext storage weakness in CVE-2025-43938.
Mandates secure authenticator management practices that prohibit plaintext password storage, directly blocking the credential disclosure vector described in the CVE.
Enforces least privilege so that even local high-privileged accounts have minimal access to credential stores, reducing the impact of the plaintext exposure.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Encryption and hashing of data-at-rest directly prevent plaintext password storage in files.
Credential management practices normally include secure storage requirements for passwords.
Protecting data-in-use can limit exposure of passwords held in memory.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Directly requires secure handling and protection of authentication information, preventing plaintext password storage.
Requires use of cryptography to protect sensitive data such as passwords at rest.
Secure coding practices would prevent developers from writing code that stores passwords in plaintext.
Mandates secure authentication mechanisms that inherently require hashed or encrypted credentials rather than plaintext.
Requires secure deletion of sensitive information, indirectly reducing exposure of stored plaintext passwords.