CVE-2025-21102

HIGH

Dell VxRail <7.0.532 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 13.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-522 CWE-256
Status published
Products (42)
dell/vxrail_d560_firmware 7.0.000 - 7.0.533
dell/vxrail_d560f_firmware 7.0.000 - 7.0.533
dell/vxrail_e460_firmware 7.0.000 - 7.0.533
dell/vxrail_e560_firmware 7.0.000 - 7.0.533
dell/vxrail_e560_vcf_firmware 7.0.000 - 7.0.533
dell/vxrail_e560f_firmware 7.0.000 - 7.0.533
dell/vxrail_e560f_vcf_firmware 7.0.000 - 7.0.533
dell/vxrail_e560n_firmware 7.0.000 - 7.0.533
dell/vxrail_e560n_vcf_firmware 7.0.000 - 7.0.533
dell/vxrail_e660_firmware 7.0.000 - 7.0.533
... and 32 more
Published Jan 08, 2025
Tracked Since Feb 18, 2026