Improper Authentication Vulnerability in Dell Storage Manager by Dell
CVE-2025-43995

9.8CRITICAL

Key Information:

Vendor

Dell

Vendor
CVE Published:
24 October 2025

What is CVE-2025-43995?

The vulnerability in Dell Storage Manager versions 20.1.21 allows unauthenticated remote attackers to exploit exposed APIs in the system. By using a specially crafted SessionKey and UserId, attackers can bypass authentication mechanisms, potentially leading to unauthorized access and manipulation of sensitive data. This critical flaw highlights the need for immediate patching to safeguard against potential breaches and unauthorized actions in the data management environment.

Affected Version(s)

Dell Storage Manager < 2020 R1.21

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank Tenable for reporting the issue.
.
CVE-2025-43995 : Improper Authentication Vulnerability in Dell Storage Manager by Dell