9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.
AI Analysis
Improper Authentication vulnerability in Dell Storage Manager, allowing unauthenticated remote attackers to bypass protection mechanisms.
Basic Information
ID
CVE-2025-43995
Source
dell
Published
Oct 24, 2025 at 14:09
Affected Product
Vendor
Dell
Product
Dell Storage Manager
Version
20.1.21
Affected Versions
Dell Dell Storage Manager N/A
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Dell
Product
Dell Storage Manager
Version
20.1.21