Description
Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-09-16
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Patch
AI Analysis

Impact

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions before 4.4.0.0 contain a use of a broken or risky cryptographic algorithm. A high‑privileged local attacker can exploit this flaw, potentially leading to the disclosure of sensitive data. The weakness involves improper algorithm selection, which may allow decryption or other cryptographic failures.

Affected Systems

The affected products are Dell Elastic Cloud Storage (ECS) versions 3.8.1.0 to 3.8.1.7 and Dell ObjectScale versions earlier than 4.4.0.0. These systems handle object storage and may expose business‑critical data if compromised.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, and the EPSS score of <1% denotes a very low probability of exploitation in the wild at this time. Because the vulnerability requires high privileged local access, the attack surface is limited to administrators or trusted users with elevated permissions. The vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of widespread exploitation, but applying the patch remains prudent.

Generated by OpenCVE AI on September 18, 2026 at 00:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Dell update that removes the risky cryptographic algorithm on ECS 3.8.1.8 or later, and on ObjectScale 4.4.0.0 or later.
  • Revoke or restrict local privileged accounts that have administrative access to ECS or ObjectScale to the minimum necessary for operations.
  • If a patch cannot be applied immediately, isolate affected services from external networks and monitor logs for anomalous cryptographic activity.

Generated by OpenCVE AI on September 18, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell elastic Cloud Storage
Vendors & Products Dell
Dell elastic Cloud Storage

Fri, 18 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Broken cryptographic algorithm leading to information exposure in Dell ECS and ObjectScale

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Elastic Cloud Storage
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T15:35:35.042Z

Reserved: 2025-04-15T21:31:17.347Z

Link: CVE-2025-36591

cve-icon Vulnrichment

Updated: 2026-09-16T15:35:29.109Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:32.867

Modified: 2026-09-16T20:37:16.870

Link: CVE-2025-36591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:37Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm