nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-24311 CVE-2025-24311
HIGH
Dell ControlVault3/ControlVault3 Plus cv_send_blockdata out-of-bounds read vulnerability
Record summary
CVE-2025-24311 has a selected CVSS score of 8.4 (high).
Description
An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 16, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
BCM5820XBrowse Broadcom / BCM5820XDefault status: unaffected | CVE List | Version range not supplied | affected |
ControlVault3Browse Dell / ControlVault3Default status: unaffected | CVE List | Before 5.15.10.14 | affected |
ControlVault3 PlusBrowse Dell / ControlVault3 PlusDefault status: unaffected | CVE List | Before 6.2.26.36 | affected |
References
3dell.com
https://www.dell.com/support/kbdoc/en-us/000276106/dsa-2025-053 talosintelligence.com
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2127