CVE-2025-25050
BaseFortify
Publication date: 2025-06-13
Last updated on: 2025-11-03
Assigner: Talos
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds write in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 and Dell ControlVault 3 Plus firmware versions prior to 5.15.10.14 and 6.2.26.36 respectively. It occurs when a specially crafted ControlVault API call is made, allowing an attacker to write data outside the intended memory boundaries.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can cause significant impact including high confidentiality, integrity, and availability losses. This means sensitive data could be exposed or altered, and system availability could be disrupted.