CVE-2025-43992
Received
Received - Intake
Authentication Bypass in Dell ECS and ObjectScale via Geo Replication
Publication date: 2026-05-11
Last updated on: 2026-05-11
Assigner: Dell
Description
Description
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | ecs | From 3.8.1.0 (inc) to 3.8.1.7 (inc) |
| dell | objectscale | to 4.3.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-302 | The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker. |