CVE-2025-26476
HIGHDell ECS <3.8.1.5/ObjectScale 4.0.0.0 - Memory Corruption
Title source: llmDescription
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Scores
CVSS v3
8.4
EPSS
0.0004
EPSS Percentile
12.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-321
CWE-798
Status
published
Affected Products (2)
dell/elastic_cloud_storage
< 3.8.1.5
dell/objectscale
Timeline
Published
Aug 04, 2025
Tracked Since
Feb 18, 2026