PT-2025-25450 · Dell · Dell Controlvault3 Plus+1

Philippe Laulheret

·

Published

2025-06-13

·

Updated

2025-08-08

·

CVE-2025-25215

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell ControlVault3 versions prior to 5.15.10.14 Dell ControlVault3 Plus versions prior to 6.2.26.36
Description An arbitrary free vulnerability exists in the cv close functionality of Dell ControlVault3 and Dell ControlVault3 Plus. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability. The vulnerability involves releasing an incorrect pointer, potentially allowing an attacker to execute arbitrary code or cause a denial of service.
Recommendations Dell ControlVault3 versions prior to 5.15.10.14: Update to version 5.15.10.14 or later. Dell ControlVault3 Plus versions prior to 6.2.26.36: Update to version 6.2.26.36 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-07625
CVE-2025-25215

Affected Products

Dell Controlvault3
Dell Controlvault3 Plus