CVE-2025-43995
BaseFortify
Publication date: 2025-10-24
Last updated on: 2025-11-04
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | storage_manager | to 2020 (exc) |
| dell | storage_manager | 2020 |
| dell | storage_manager | 2020 |
| dell | storage_manager | 2020 |
| dell | storage_manager | 2020 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Authentication issue in Dell Storage Center - Dell Storage Manager version 20.1.21. An unauthenticated remote attacker can exploit it by accessing APIs exposed by ApiProxy.war in DataCollectorEar.ear using special SessionKey and UserId values. These special user IDs are created for specific purposes in compellentservicesapi, allowing the attacker to bypass protection mechanisms and authentication controls.
How can this vulnerability impact me? :
The vulnerability allows an unauthenticated remote attacker to bypass authentication and gain unauthorized access to sensitive APIs. This can lead to a complete compromise of confidentiality, integrity, and availability of the affected system, potentially allowing the attacker to manipulate data, disrupt services, or gain further access within the environment.