Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dell:storage_manager:*:*:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:* |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell storage Manager |
|
| Vendors & Products |
Dell
Dell storage Manager |
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published: 2025-10-24T14:09:55.238Z
Updated: 2025-10-25T03:56:07.748Z
Reserved: 2025-04-21T05:03:43.637Z
Link: CVE-2025-43995
No data.
Status : Analyzed
Published: 2025-10-24T15:15:38.380
Modified: 2025-11-04T14:43:05.420
Link: CVE-2025-43995
No data.