5.6
CVE-2025-43992
- EPSS 0.08%
- Veröffentlicht 11.05.2026 10:16:12
- Zuletzt bearbeitet 16.05.2026 02:52:50
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Elastic Cloud Storage Version >= 3.8.1.0 < 4.3.0.0
Dell ≫ Objectscale Version < 4.3.0.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.244 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security_alert@emc.com | 5.6 | 2.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-302 Authentication Bypass by Assumed-Immutable Data
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.