CVE-2025-26478

Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*

History

01 Aug 2025, 20:55

Type Values Removed Values Added
First Time Dell elastic Cloud Storage
Dell
Dell objectscale
CPE cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-in/000300068/dsa-2025-097-security-update-for-dell-objectscale-4-0-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-in/000300068/dsa-2025-097-security-update-for-dell-objectscale-4-0-multiple-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

17 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 12:15

Updated : 2025-08-01 20:55


NVD link : CVE-2025-26478

Mitre link : CVE-2025-26478


JSON object : View

Products Affected

dell

  • elastic_cloud_storage
  • objectscale
CWE
CWE-295

Improper Certificate Validation