PT-2025-15228 · Dell · Powermax+1

Published

2025-04-03

·

Updated

2025-04-08

·

CVE-2025-27686

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dell Unisphere for PowerMax versions prior to 10.2.0.9 PowerMax versions prior to 9.2.4.15
Description The issue is related to an Improper Neutralization of Special Elements used in an LDAP Query, also known as 'LDAP Injection'. A high privileged attacker with remote access could potentially exploit this, leading to Script injection.
Recommendations For Dell Unisphere for PowerMax versions prior to 10.2.0.9, update to version 10.2.0.9 or later. For PowerMax versions prior to 9.2.4.15, update to version 9.2.4.15 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-05919
CVE-2025-27686

Affected Products

Dell Emc Unisphere For Powermax
Powermax