Impact
Dell ObjectScale prior to 4.3.0.1 contains a CWE‑532 weakness—Insertion of Sensitive Information into Log File—in svc_tools. A low‑privileged attacker with local access can trigger the application to write confidential data, such as credentials or secrets, directly to system logs. The disclosure of this information allows attackers to compromise confidentiality by retrieving secrets that should remain protected.
Affected Systems
Dell ObjectScale versions earlier than 4.3.0.1 are affected. No specific patch versions are listed beyond 4.3.0.1, so any release with a version number less than 4.3.0.1 is at risk.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium range in terms of confidentiality impact. The EPSS score is not available and Dell ObjectScale is not listed in the CISA KEV catalog, indicating no known active exploits as of this analysis. The likely attack vector is local: an attacker who has low‑privileged access to the system and the svc_tools directory can exploit the flaw. While the risk is moderate, the potential leakage of sensitive data justifies prompt remediation.
OpenCVE Enrichment