CVE-2025-46636
BaseFortify
Publication date: 2025-12-09
Last updated on: 2025-12-10
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | encryption | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-59 | The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Dell Encryption versions prior to 11.12.1 is an Improper Link Resolution Before File Access ('Link Following') issue. It allows a low privileged attacker with local access to potentially exploit the system by manipulating symbolic links before a file is accessed, which can lead to information tampering.
How can this vulnerability impact me? :
The vulnerability can lead to information tampering by a low privileged attacker with local access. This means an attacker could alter information or data by exploiting the improper link resolution before file access.