Improper Authentication Vulnerability in Dell Storage Manager by Dell
CVE-2025-43995
9.8CRITICAL
What is CVE-2025-43995?
The vulnerability in Dell Storage Manager versions 20.1.21 allows unauthenticated remote attackers to exploit exposed APIs in the system. By using a specially crafted SessionKey and UserId, attackers can bypass authentication mechanisms, potentially leading to unauthorized access and manipulation of sensitive data. This critical flaw highlights the need for immediate patching to safeguard against potential breaches and unauthorized actions in the data management environment.
Affected Version(s)
Dell Storage Manager < 2020 R1.21
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank Tenable for reporting the issue.