HomeSecurityCritical vulnerabilities in Dell Storage Manager allow compromise

Critical vulnerabilities in Dell Storage Manager allow compromise

Dell Technologies has disclosed three critical vulnerabilities in its Storage Manager that could allow attackers to bypass authentication, disclose sensitive information, and gain unauthorized access to systems.

See also: Critical vulnerabilities in Dell laptops threaten users

Dell vulnerabilities

Announced on October 24, 2025 , they affect versions of Dell Storage Manager up to 20.1.21 and pose significant risks to organizations that rely on the tool to manage storage arrays. With CVSS scores ranging from 6.5 to 9.8, the vulnerabilities highlight ongoing challenges in securing management interfaces, potentially allowing remote exploitation without user interaction.

The most severe issue, CVE-2025-43995 , has a CVSS baseline score of 9.8 , ranking it as critical. This improper authentication flaw is located in the DSM Data Collector component . An unauthenticated attacker with remote access could exploit exposed APIs in the ApiProxy.war file within DataCollectorEar.ear by creating a special SessionKey and UserId .

These credentials leverage special users created in the Compellent Services API for internal purposes, allowing attackers to completely bypass protection mechanisms.

Exploitation could lead to a complete system compromise, including high confidentiality, integrity, and availability impacts, as detailed in the vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

See also: Dell says data leaked by hackers is fake

Critical vulnerabilities in Dell Storage Manager allow compromise

Complementing this is CVE-2025-43994, rated 8.6, which involves missing authentication for a critical function. Again targeting DSM 20.1.21, this vulnerability allows unauthorized remote attackers to trigger information disclosure, while disrupting service availability.

The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H indicates low complexity and no privileges required, making it a primary target for opportunistic hackers. Attackers could exfiltrate configuration data or operational details, opening the way for broader network intrusions.

A third vulnerability, CVE-2025-46425 , affects version 20.1.20 and introduces an inappropriate restriction on XML external entity references , earning a score of 6.5 .

While low privileges are required, a remote intruder could exploit it to read sensitive files, leading to unauthorized access without directly affecting integrity or availability (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). This XXE security flaw underscores the risks of parsing untrusted XML inputs in storage management tools.

See also: Dell confirms platform breach by World Leaks

Critical vulnerabilities in Dell Storage Manager allow compromise

Dell urges customers to assess risks using both core and environmental CVSS scores, with an emphasis on immediate updates.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS