Authentication Bypass in Dell ECS and ObjectScale Products
CVE-2025-43992

5.6MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
11 May 2026

What is CVE-2025-43992?

Dell ECS versions 3.8.1.0 to 3.8.1.7 and Dell ObjectScale prior to version 4.3.0.0 are vulnerable to an authentication bypass due to issues in Geo replication. This can allow an unauthenticated remote attacker to potentially gain unauthorized access to sensitive data transmitted during the replication process. Therefore, it is crucial for users to apply the latest security updates provided by Dell to mitigate this risk effectively.

Affected Version(s)

ECS 0 < 4.3.0.0 or later

ObjectScale 0 < 4.3.0.0 or later

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.