PT-2025-23097 · Dell · Dell Powerstore

CVE-2025-36572

·

Publicado

2025-05-28

·

Atualizado

2025-05-28

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell PowerStore version 4.0.0.0
Description The issue concerns the use of hard-coded credentials in the PowerStore image file. A low-privileged attacker with remote access and knowledge of these credentials could exploit this to gain unauthorized access based on the hardcoded account's privileges.
Recommendations For version 4.0.0.0, consider changing the hard-coded credentials to unique, strong passwords to prevent unauthorized access. As a temporary workaround, restrict remote access to the PowerStore image file until a patch is available.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-10457
CVE-2025-36572

Produtos afetados

Dell Powerstore