Use of a Risky Cryptographic Algorithm in Dell PowerFlex Manager
CVE-2025-46371

3.6LOW

What is CVE-2025-46371?

Dell PowerFlex Manager, specifically in versions up to and including 4.6.2, is vulnerable due to the use of a broken or risky cryptographic algorithm in its SSH implementation. This flaw allows a low-privileged attacker with local access to potentially exploit the vulnerability, enabling them to bypass critical protection mechanisms. This situation underscores the importance of keeping software and firmware updated and ensures that cryptographic algorithms in use are strong and secure.

Affected Version(s)

PowerFlex Manager 0 <= 4.6.2

PowerFlex Manager (Appliance) 0

PowerFlex Manager (Appliance) 0

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.