CVE-2025-43995

🟠 Łataj w tym tygodniu

Obejście uwierzytelnienia w Dell Storage Manager umożliwia zdalny dostęp do API bez hasła.

CVSS
9.8
EPSS
0.8%
Exploit
none
Vendor
dell
Opis źródłowy (NVD)

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

auth-bypass Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.8%
Opublikowano (NVD)2025-10-24 15:15:38 UTC
Ostatnia modyfikacja (NVD)2026-09-30 23:10:00 UTC
Referencje