CVE-2025-26478

Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

History

01 Aug 2025, 20:55

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-in/000300068/dsa-2025-097-security-update-for-dell-objectscale-4-0-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-in/000300068/dsa-2025-097-security-update-for-dell-objectscale-4-0-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
First Time Dell objectscale
Dell elastic Cloud Storage
Dell
Summary
  • (es) Dell ECS versión 3.8.1.4 y anteriores contienen una vulnerabilidad de validación incorrecta de certificados. Un atacante no autenticado con acceso a la red adyacente podría explotar esta vulnerabilidad, lo que podría provocar la divulgación de información.

17 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 12:15

Updated : 2025-08-01 20:55


NVD link : CVE-2025-26478

Mitre link : CVE-2025-26478

CVE.ORG link : CVE-2025-26478


JSON object : View

Products Affected

dell

  • objectscale
  • elastic_cloud_storage
CWE
CWE-295

Improper Certificate Validation