Use of Hard-coded Cryptographic Key in Dell ECS and ObjectScale
CVE-2025-26476

8.4HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
4 August 2025

What is CVE-2025-26476?

Dell ECS and ObjectScale are susceptible to a vulnerability stemming from the use of hard-coded cryptographic keys. This weakness allows an unauthenticated attacker with local access to exploit the flaw, resulting in unauthorized access to sensitive data and potential system manipulation. It is crucial for organizations using affected versions to apply the necessary security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

ECS < 3.8.1.5

ObjectScale 4.0.0.0 < 4.0.0.0 or later

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.