CVE-2025-30105

HIGH

Dell XtremIO 6.4.0-22 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 7.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (2)
dell/techadvisor 2.6 - 3.4
dell/xtremio_management_server < 6.4.3
Published Jul 30, 2025
Tracked Since Feb 18, 2026