Record summary

CVE-2025-24311 has a selected CVSS score of 8.4 (high).

Description

An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 16, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListVersion range not suppliedaffected

Default status: unaffected

CVE ListBefore 5.15.10.14affected

Default status: unaffected

CVE ListBefore 6.2.26.36affected

References

3