DSA-2025-434: Security Update for Dell PowerFlex Appliance Multiple Third-Party Component Vulnerabilities
Yhteenveto: Dell PowerFlex Appliance remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Tämä artikkeli koskee tuotetta
Tämä artikkeli ei koske tuotetta
Tämä artikkeli ei liity tiettyyn tuotteeseen.
Tässä artikkelissa ei yksilöidä kaikkia tuoteversioita.
Vaikutus
Critical
Tiedot
| Third-party Component | CVEs | More Information |
| Dell PowerEdge Server BIOS | CVE-2024-31068, CVE-2024-28047, CVE-2024-39279, CVE-2024-36293, CVE-2024-28956, CVE-2024-45332, CVE-2025-24513, CVE-2025-24514, CVE-2025-1097, CVE-2025-1098, CVE-2025-1974, CVE-2024-36357, CVE-2024-36350, CVE-2024-36348, CVE-2024-33607, CVE-2025-20109, CVE-2025-20044, CVE-2024-56161, CVE-2024-25571, CVE-2024-37020, CVE-2024-21859, CVE-2024-31155 | DSA-2024-381, DSA-2025-041, DSA-2025-156, DSA-2025-181, DSA-2025-324, DSA-2025-156, DSA-2025-040, DSA-2025-042 |
| iDRAC | CVE-2025-26482, CVE-2025-22397, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50602, CVE-2024-2961, CVE-2024-52533, CVE-2023-6780, CVE-2025-26466, CVE-2026-26945 | DSA-2025-046,DSA-2025-146, DSA-2025-145, DSA-2026-113 |
| VMware | CVE-2025-41225, CVE-2025-41226, CVE-2025-41227, CVE-2025-41228, CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, CVE-2025-41239, CVE-2025-41241, CVE-2025-41250 | VMSA-2025-0010 |
| Sudo | CVE-2025-32463 | http://nvd.nist.gov/ |
| Numpy | CVE-2021-41495 | http://nvd.nist.gov/ |
| OpenJDK | CVE-2025-21502 | http://nvd.nist.gov/ |
| OpenSSH | CVE-2023-48795 | http://nvd.nist.gov/ |
| Go | CVE-2024-24790 | http://nvd.nist.gov/ |
| PostgreSQL | CVE-2024-0985, CVE-2023-5869 | http://nvd.nist.gov/ |
| Redis | CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819 | http://nvd.nist.gov/ |
| IntelAdapters | CVE-2024-24852, CVE-2024-36274 | DSA-2025-042 |
| bundler | CVE-2020-36327 | http://nvd.nist.gov/ |
| cryptography | CVE-2023-50782 | http://nvd.nist.gov/ |
| Docker | CVE-2024-41110 | http://nvd.nist.gov/ |
| GoFiber | CVE-2024-38513 | http://nvd.nist.gov/ |
| GoGo Protobuf | CVE-2021-3121 | http://nvd.nist.gov/ |
| pgproto3, pgx | CVE-2024-27304 | http://nvd.nist.gov/ |
| glibc | CVE-2024-2961, CVE-2024-33599, CVE-2024-33600 | http://nvd.nist.gov/ |
| golang.org/x/crypto | CVE-2022-27191 | http://nvd.nist.gov/ |
| java-17-openjdk | CVE-2024-20918, CVE-2024-20932, CVE-2024-20952, CVE-2024-21147 | http://nvd.nist.gov/ |
| keycloak-core | CVE-2024-10039, CVE-2023-6841 | http://nvd.nist.gov/ |
| keycloak-quarkus-server | CVE-2024-10451 | http://nvd.nist.gov/ |
| keycloak-saml-core | CVE-2024-8698 | http://nvd.nist.gov/ |
| keycloak-services | CVE-2024-3656, CVE-2024-7341, CVE-2024-4540, CVE-2024-1132, CVE-2024-1249, CVE-2023-6291, CVE-2024-2419, CVE-2024-10270 | http://nvd.nist.gov/ |
| krb5 | CVE-2024-26458, CVE-2024-26461, CVE-2024-26462, CVE-2024-37370 | http://nvd.nist.gov/ |
| libxml2-2 | CVE-2024-56171 | http://nvd.nist.gov/ |
| nokogiri | CVE-2025-24855, CVE-2024-55549 | http://nvd.nist.gov/ |
| postgresql15 | CVE-2025-1094 | http://nvd.nist.gov/ |
| rexml | CVE-2021-28965, CVE-2024-43398 | http://nvd.nist.gov/ |
| go-grpc-compression | CVE-2024-36129 | http://nvd.nist.gov/ |
| stdlib | CVE-2022-30632, CVE-2023-45288, CVE-2024-24791, CVE-2024-34156 | http://nvd.nist.gov/ |
| Keycloak | CVE-2025-7962, CVE-2025-49574, CVE-2025-55163, CVE-2025-58057, CVE-2025-48924, CVE-2025-9162, CVE-2025-8419, CVE-2025-7784, CVE-2025-7365, CVE-2025-50106, CVE-2025-30749 | http://nvd.nist.gov/ |
| SQLite | CVE-2023-7104 | http://nvd.nist.gov/ |
| Python | CVE-2024-35195, CVE-2022-40899, CVE-2024-6345 | http://nvd.nist.gov/ |
| CPython | CVE-2024-7592, CVE-2024-6232, CVE-2024-3219, CVE-2024-6923 | http://nvd.nist.gov/ |
| urllib3 | CVE-2024-37891 | http://nvd.nist.gov/ |
| Python-Requests | CVE-2023-32681 | http://nvd.nist.gov/ |
| XZ Utils | CVE-2024-47611, CVE-2020-22916 | http://nvd.nist.gov/ |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-46371 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | 3.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
| CVE-2025-32751 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2025-32750 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVE-2025-32749 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2025-32747 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2025-32746 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. | 4.0 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| CVE-2025-32745 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering. | 4.2 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2025-26483 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. | 6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-46371 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | 3.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
| CVE-2025-32751 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2025-32750 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVE-2025-32749 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2025-32747 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2025-32746 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information. | 4.0 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| CVE-2025-32745 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering. | 4.2 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2025-26483 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. | 6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Tuotteet, joihin asia vaikuttaa, ja tilanteen korjaaminen
| Product | Affected Versions | Remediated Versions | Link |
| PowerFlex Appliance | Versions prior to IC 48.378.00 | Version IC 48.378.00 | IC release |
| PowerFlex Appliance | Versions prior to IC 48.383.00 | Version IC 48.383.00 | IC release |
| Product | Affected Versions | Remediated Versions | Link |
| PowerFlex Appliance | Versions prior to IC 48.378.00 | Version IC 48.378.00 | IC release |
| PowerFlex Appliance | Versions prior to IC 48.383.00 | Version IC 48.383.00 | IC release |
Versiohistoria
| Revision | Date | Description |
| 1.0 | 2025-11-13 | Initial Release |
| 2.0 | 2025-11-17 | Updated CVE Identifier, Third Party Components: Added CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819 |
| 3.0 | 2025-11-24 | Updated CVE Identifier, Third Party Components: Added CVE-2024-24852, CVE-2024-36274 |
| 4.0 | 2025-11-26 | Added details for CVE-2025-41250 |
| 5.0 | 2025-12-11 | Update addressed 40 CVEs in Third Party Components |
| 6.0 | 2026-01-20 | Updated CVE Identifier, Third Party Components: Added Keycloak 11 CVEs |
| 7.0 | 2026-03-18 | Added details for CVE-2026-26945 |
| 8.0 | 2026-04-24 | formating data to link some CVEs to their OSS Library |
Asiaan liittyvät tiedot
Vastuuvapauslauseke
Tuotteet, joihin vaikutus kohdistuu
PowerFlex Appliance, ScaleIO, PowerFlex appliance Intelligent Catalog SoftwareArtikkelin ominaisuudet
Artikkelin numero: 000391392
Artikkelin tyyppi: Dell Security Advisory
Viimeksi muutettu: 24 huhtik. 2026
Etsi vastauksia kysymyksiisi muilta Dell-käyttäjiltä
Tukipalvelut
Tarkista, kuuluuko laitteesi tukipalveluiden piiriin.