DSA-2026-260: Security Update for Dell PowerProtect Data Manager Appliance DM5510 Multiple Vulnerabilities

Oversigt: Dell PowerProtect Data Manager Appliance DM5510 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. ...

Denne artikel gælder for Denne artikel gælder ikke for Denne artikel er ikke knyttet til et bestemt produkt. Det er ikke alle produktversioner, der er identificeret i denne artikel.

Virkning

High

Oplysninger

Third-party Component CVEs  More Information 
libglib-2_0-0 2.70.5 CVE-2025-3360, CVE-2025-4373 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
perl-base 5.26.1 CVE-2025-40909 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
krb5 1.19.2 CVE-2025-24528 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
update-alternatives 1.19.0.4 CVE-2025-6297 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-25909 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to the launch of phishing attacks. 3.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25910 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25913 Dell PowerProtect Data Manager Appliance DM5510, version 6.22.0.0, contain(s) a NULL Pointer Dereference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25914 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-25909 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to the launch of phishing attacks. 3.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25910 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25913 Dell PowerProtect Data Manager Appliance DM5510, version 6.22.0.0, contain(s) a NULL Pointer Dereference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25914 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies anbefaler, at alle kunder tager hensyn til både CVSS-basisresultatet og alle relevante tidsmæssige og miljømæssige resultater, som kan have betydning for den potentielle alvorsgrad, der er forbundet med en bestemt sikkerhedsrisiko.

Berørte produkter og udbedring

Product Affected Versions Remediated Versions Link
Dell PowerProtect Data Manager Appliance DM5510 Version 6.22.0.0 Version 20.1.0.0 or later Power Protect DM5510 Drivers & Downloads
Product Affected Versions Remediated Versions Link
Dell PowerProtect Data Manager Appliance DM5510 Version 6.22.0.0 Version 20.1.0.0 or later Power Protect DM5510 Drivers & Downloads

Revisionshistorik

RevisionDateDescription
1.02026-06-22Initial Release

Relaterede oplysninger

Berørte produkter

PowerProtect Data Manager Appliance, PowerProtect DM5510
Artikelegenskaber
Artikelnummer: 000480323
Artikeltype: Dell Security Advisory
Senest ændret: 22 jun. 2026
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.