CVE-2025-23377: Dell Powerprotect Data Manager

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.

Affected products

  • Dell Powerprotect Data Manager: version 19.17 only; version 19.18 only

Published 2025-04-28. Last modified 2026-06-17.