CVE-2025-43995
🟠 Łataj w tym tygodniu
Obejście uwierzytelnienia w Dell Storage Manager umożliwia zdalny dostęp do API bez hasła.
CVSS
9.8
EPSS
0.8%
Exploit
none
Vendor
dell
Opis źródłowy (NVD)
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.
auth-bypass
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.8% |
| Opublikowano (NVD) | 2025-10-24 15:15:38 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |