CVE 9.8 CRITICAL

CVE-2025-43995_CVE-2025-43995

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

AI Analysis

Improper Authentication vulnerability in Dell Storage Manager, allowing unauthenticated remote attackers to bypass protection mechanisms.

Basic Information

ID CVE-2025-43995
Source dell
Published Oct 24, 2025 at 14:09

Affected Product

Vendor Dell
Product Dell Storage Manager
Version 20.1.21
Affected Versions Dell Dell Storage Manager N/A

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Dell
Product Dell Storage Manager
Version 20.1.21

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.