HomeDellCVE-2025-43995

CVE-2025-43995

CRITICAL
9.8CVSS
Published: 2025-10-24
Updated: 2025-11-04
AI Analysis

Description

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-287

Metadata

Primary Vendor
DELL
Published
10/24/2025
Last Modified
11/4/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

dell : storage_managerdell : storage_managerdell : storage_managerdell : storage_managerdell : storage_manager

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief