Out-of-Bounds Read and Write Vulnerabilities in Dell ControlVault3 and ControlVault3 Plus
CVE-2025-36463

7.3HIGH

Key Information:

Vendor

Broadcom

Vendor
CVE Published:
17 November 2025

What is CVE-2025-36463?

Multiple out-of-bounds read and write vulnerabilities have been identified in the functionality of the ControlVault WBDI Driver, specifically impacting Dell ControlVault3 versions earlier than 5.15.14.19 and Dell ControlVault3 Plus versions prior to 6.2.36.47. These vulnerabilities arise from improper handling of WinBioControlUnit API calls that can lead to memory corruption. An exploit can be triggered by issuing a WinBioControlUnit call with a specified control code, leading to unintended memory access beyond the bounds of the allocated SendBuffer. Although the conditions for successful exploitation are strict, the potential for Denial of Service attacks exists.

Affected Version(s)

BCM5820X NA

ControlVault3 0 < 5.15.14.19

ControlVault3 Plus 0 < 6.2.36.47

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Philippe Laulheret of Cisco Talos.
.
CVE-2025-36463 : Out-of-Bounds Read and Write Vulnerabilities in Dell ControlVault3 and ControlVault3 Plus