Out-of-Bounds Read in Dell ControlVault3 and ControlVault3 Plus
CVE-2025-24311

8.4HIGH

Key Information:

Vendor

Broadcom

Vendor
CVE Published:
13 June 2025

What is CVE-2025-24311?

An out-of-bounds read vulnerability has been identified in the functionality of Dell ControlVault3 and ControlVault3 Plus. This issue arises due to improper handling in the cv_send_blockdata method, allowing an attacker to exploit this flaw through specially crafted ControlVault API calls. When invoked, such calls can lead to sensitive information being inadvertently exposed, potentially compromising system security.

Affected Version(s)

BCM5820X NA

ControlVault3 0 < 5.15.10.14

ControlVault3 Plus 0 < 6.2.26.36

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Philippe Laulheret of Cisco Talos.
.
CVE-2025-24311 : Out-of-Bounds Read in Dell ControlVault3 and ControlVault3 Plus