Логотип exploitDog
bind:CVE-2025-24919
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-24919

Количество 3

Количество 3

nvd логотип

CVE-2025-24919

8 месяцев назад

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-fvxq-m6wq-rqqv

8 месяцев назад

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2025-07431

8 месяцев назад

Уязвимость функции cvhDecapsulateCmd() пакета драйверов для управления безопасностью Dell ControlVault3, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-24919

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-fvxq-m6wq-rqqv

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
fstec логотип
BDU:2025-07431

Уязвимость функции cvhDecapsulateCmd() пакета драйверов для управления безопасностью Dell ControlVault3, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
0%
Низкий
8 месяцев назад

Уязвимостей на страницу