DSA-2026-260: Security Update for Dell PowerProtect Data Manager Appliance DM5510 Multiple Vulnerabilities

Riepilogo: Dell PowerProtect Data Manager Appliance DM5510 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. ...

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

High

Dettagli

Third-party Component CVEs  More Information 
libglib-2_0-0 2.70.5 CVE-2025-3360, CVE-2025-4373 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
perl-base 5.26.1 CVE-2025-40909 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
krb5 1.19.2 CVE-2025-24528 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.
update-alternatives 1.19.0.4 CVE-2025-6297 https://nvd.nist.gov/vuln/search This hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-25909 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to the launch of phishing attacks. 3.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25910 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25913 Dell PowerProtect Data Manager Appliance DM5510, version 6.22.0.0, contain(s) a NULL Pointer Dereference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25914 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-25909 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to the launch of phishing attacks. 3.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25910 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25913 Dell PowerProtect Data Manager Appliance DM5510, version 6.22.0.0, contain(s) a NULL Pointer Dereference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L This hyperlink is taking you to a website outside of Dell Technologies.
CVE-2026-25914 Dell PowerProtect Data Manager Appliance DM5510, version(s) 6.22.0.0, contain(s) an Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N This hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Product Affected Versions Remediated Versions Link
Dell PowerProtect Data Manager Appliance DM5510 Version 6.22.0.0 Version 20.1.0.0 or later Power Protect DM5510 Drivers & Downloads
Product Affected Versions Remediated Versions Link
Dell PowerProtect Data Manager Appliance DM5510 Version 6.22.0.0 Version 20.1.0.0 or later Power Protect DM5510 Drivers & Downloads

Cronologia delle revisioni

RevisionDateDescription
1.02026-06-22Initial Release

Informazioni correlate

Prodotti interessati

PowerProtect Data Manager Appliance, PowerProtect DM5510
Proprietà dell'articolo
Numero articolo: 000480323
Tipo di articolo: Dell Security Advisory
Ultima modifica: 22 giu 2026
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.