CVE-2025-36568: High severity Dell PowerProtect Data Domain BoostFS for Client vulnerability
Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to credential exposure. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36568?
CVE-2025-36568 is rated as having a low severity due to the attacker's low privilege requirement for exploitation.
How do I fix CVE-2025-36568?
To fix CVE-2025-36568, update Dell PowerProtect Data Domain BoostFS for Client to a patched version that addresses the insufficiently protected credentials.
Who is affected by CVE-2025-36568?
CVE-2025-36568 affects users of Dell PowerProtect Data Domain BoostFS for Client versions 7.7.1.0 through 8.5, and specific LTS versions.
What are the potential impacts of CVE-2025-36568?
Exploitation of CVE-2025-36568 could allow a low privileged attacker to gain unauthorized access to sensitive credentials.
When was CVE-2025-36568 disclosed?
CVE-2025-36568 was disclosed in 2026 as part of Dell's security updates addressing multiple vulnerabilities.