8.8
CVE-2025-22477
- EPSS 0.29%
- Veröffentlicht 06.05.2025 16:03:29
- Zuletzt bearbeitet 13.05.2025 20:17:36
- Erkennungen
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Storage Manager Version 16.3.20
Dell ≫ Storage Manager Version 2016 Update r2.1
Dell ≫ Storage Manager Version 2020 Update r1
Dell ≫ Storage Manager Version 2020 Update r1.10
Dell ≫ Storage Manager Version 2020 Update r1.2
Dell ≫ Storage Manager Version 2020 Update r1.20
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| EMC | 8.3 | 2.8 | 5.5 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://www.dell.com/support/kbdoc/en-us/000317318/dsa-2025-191-security-update-for-storage-center-dell-storage-manager-vulnerabilities