Dell Vulnerabilities and Affected Products
Vulnerabilities associated with ControlVault3 Plus.
Products
Clear product- PowerScale OneFS173 vulnerabilities
- CPG BIOS110 vulnerabilities
- Unity61 vulnerabilities
- Wyse Management Suite53 vulnerabilities
- PowerProtect Data Domain49 vulnerabilities
- PowerEdge Platform33 vulnerabilities
- SmartFabric OS10 Software28 vulnerabilities
- PowerProtect DD25 vulnerabilities
- Integrated Dell Remote Access Controller (iDRAC)24 vulnerabilities
- PowerProtect Data Manager23 vulnerabilities
- PowerStore23 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202322 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202421 vulnerabilities
- CloudLink20 vulnerabilities
- Unisphere for PowerMax19 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release18 vulnerabilities
- powerscale_onefs18 vulnerabilities
- NetWorker16 vulnerabilities
- ECS15 vulnerabilities
- PowerProtect Data Domain with Data Domain Operating System (DD OS) LTS202515 vulnerabilities
- Avamar14 vulnerabilities
- Alienware Command Center (AWCC)13 vulnerabilities
- ControlVault313 vulnerabilities
- ControlVault3 Plus13 vulnerabilities
- Dell OpenManage Enterprise13 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-31649HIGH | Dell ControlVault3 ControlVault WBDI Driver hard-coded password vulnerabilityA hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this vulnerability. CWE-908Nov 17, 2025 | CVSS8.7v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-31361HIGH | Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter privilege escalation vulnerabilityA privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to privilege escalation. An attacker can issue an api call to trigger this vulnerability. CWE-908Nov 17, 2025 | CVSS8.7v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36463HIGH | Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityMultiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 4 (`WBIO_USH_ADD_RECOR… CWE-805Nov 17, 2025 | CVSS7.3v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36462HIGH | Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityMultiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 3 (`WBIO_USH_CREATE_CH… CWE-805Nov 17, 2025 | CVSS7.3v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36461HIGH | Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityMultiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 0 (`WBIO_USH_GET_TEMPL… CWE-805Nov 17, 2025 | CVSS7.3v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36460HIGH | Dell ControlVault3 ControlVault WBDI Driver Broadcom Storage Adapter out-of-bounds write vulnerabilityMultiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 2 (`WBIO_USH_GET_IDENT… CWE-805Nov 17, 2025 | CVSS7.3v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-32089HIGH | Dell ControlVault3 CvManager_SBI buffer overflow vulnerabilityA buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call to trigger this vulnerability. CWE-120Nov 17, 2025 | CVSS8.8v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36553HIGH | Dell ControlVault3 CvManager buffer overflow vulnerabilityA buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. CWE-120Nov 17, 2025 | CVSS8.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24919HIGH | Dell ControlVault3/ControlVault3 Plus deserialization of untrusted input vulnerabilityA deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability. CWE-502Jun 13, 2025 | CVSS8.1v3.1 | EPSS1.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-25215HIGH | Dell ControlVault3/ControlVault3 Plus cv_close arbitrary free vulnerabilityAn arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability. CWE-763Jun 13, 2025 | CVSS8.8v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-25050HIGH | Dell ControlVault3/ControlVault3 Plus cv_upgrade_sensor_firmware out-of-bounds write vulnerabilityAn out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this vulnerability. CWE-787Jun 13, 2025 | CVSS8.8v3.1 | EPSS1.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24922HIGH | Dell ControlVault3/ControlVault3 Plus securebio_identify stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call to trigger this vulnerability. CWE-121Jun 13, 2025 | CVSS8.8v3.1 | EPSS2.59% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24311HIGH | Dell ControlVault3/ControlVault3 Plus cv_send_blockdata out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability. CWE-125Jun 13, 2025 | CVSS8.4v3.1 | EPSS1.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |