Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
References
Configurations
Configuration 1 (hide)
|
History
01 Aug 2025, 20:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dell elastic Cloud Storage
Dell Dell objectscale |
|
CPE | cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:* cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* |
|
References | () https://www.dell.com/support/kbdoc/en-in/000300068/dsa-2025-097-security-update-for-dell-objectscale-4-0-multiple-vulnerabilities - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
17 Apr 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-17 12:15
Updated : 2025-08-01 20:55
NVD link : CVE-2025-26478
Mitre link : CVE-2025-26478
JSON object : View
Products Affected
dell
- elastic_cloud_storage
- objectscale
CWE
CWE-295
Improper Certificate Validation