Host Header Injection Vulnerability in Dell PowerFlex Rack
CVE-2025-32748

4.3MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
17 June 2026

What is CVE-2025-32748?

The Dell PowerFlex Rack suffers from a Host Header Injection vulnerability that may allow unauthenticated remote attackers to exploit it and initiate redirection attacks. Proper security measures should be taken to mitigate this vulnerability.

Affected Version(s)

PowerFlex rack 0 < 3.9.1.1 or later

PowerFlex rack 0 < 3.8.4.1 or later

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.