Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-43995

Опубликовано: 24 окт. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dell:storage_manager:*:*:*:*:*:*:*:*
Версия до 2020 (исключая)
cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00314
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
github
4 месяца назад

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

EPSS

Процентиль: 54%
0.00314
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287