Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11506 | Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 01 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell elastic Cloud Storage Dell objectscale |
|
| CPEs | cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dell
Dell elastic Cloud Storage Dell objectscale |
Thu, 17 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Apr 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2025-04-17T13:15:12.492Z
Reserved: 2025-02-11T06:06:12.147Z
Link: CVE-2025-26478
Updated: 2025-04-17T13:15:03.455Z
Status : Analyzed
Published: 2025-04-17T12:15:15.307
Modified: 2025-08-01T20:55:44.843
Link: CVE-2025-26478
No data.
OpenCVE Enrichment
No data.
EUVD