CVE-2025-26332
BaseFortify
Publication date: 2025-07-30
Last updated on: 2025-07-31
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | xtremio_x2 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the insertion of sensitive information into a log file in TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2. A low privileged attacker with local access could exploit this to expose sensitive information, such as credentials, which could then be used to access the application with the privileges of the compromised account.
How can this vulnerability impact me? :
The vulnerability can lead to information exposure, allowing an attacker to obtain sensitive credentials from log files. This could enable the attacker to gain unauthorized access to the vulnerable application with the privileges of the compromised account, potentially leading to further compromise and damage.