PT-2025-25446 · Dell · Dell Controlvault3 Plus+1

Philippe Laulheret

·

Published

2025-06-13

·

Updated

2025-08-08

·

CVE-2025-24922

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell ControlVault3 versions prior to 5.15.10.14 Dell ControlVault3 Plus versions prior to 6.2.26.36
Description A stack-based buffer overflow vulnerability exists in the securebio identify functionality. A specially crafted malicious cv object can lead to arbitrary code execution. An attacker can issue an API call to trigger this vulnerability.
Recommendations Update Dell ControlVault3 to version 5.15.10.14 or later. Update Dell ControlVault3 Plus to version 6.2.26.36 or later.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-07433
CVE-2025-24922

Affected Products

Dell Controlvault3
Dell Controlvault3 Plus