CVE-2025-38739
BaseFortify
Publication date: 2025-08-04
Last updated on: 2025-08-18
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | digital_delivery | to 5.6.1.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Dell Digital Delivery versions prior to 5.6.1.0 involves Insufficiently Protected Credentials, which means that sensitive credential information is not adequately secured. A remote unauthenticated attacker could exploit this weakness to gain access to this information, leading to information disclosure.
How can this vulnerability impact me? :
Exploitation of this vulnerability could allow a remote attacker to obtain sensitive credential information without authentication, potentially leading to unauthorized access or further attacks. This could compromise confidentiality and availability of affected systems.