PT-2025-25450 · Dell · Dell Controlvault3 Plus +1

Philippe Laulheret

·

Published

2025-06-13

·

Updated

2025-08-08

·

CVE-2025-25215

CVSS v3.1
8.8
VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Dell ControlVault3 versions prior to 5.15.10.14

Dell ControlVault3 Plus versions prior to 6.2.26.36

**Description:**

An arbitrary free vulnerability exists in the `cv close` functionality of Dell ControlVault3 and Dell ControlVault3 Plus. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability. The vulnerability involves releasing an incorrect pointer, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

**Recommendations:**

Dell ControlVault3 versions prior to 5.15.10.14: Update to version 5.15.10.14 or later.

Dell ControlVault3 Plus versions prior to 6.2.26.36: Update to version 6.2.26.36 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-07625
CVE-2025-25215

Affected Products

Dell Controlvault3
Dell Controlvault3 Plus