CVE-2025-31649

HIGH

Dell ControlVault3 <5.15.14.19 & Dell ControlVault3 Plus <6.2.36.47...

Title source: llm
STIX 2.1

Description

A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this vulnerability.

Scores

CVSS v3 8.7
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-908
Status published
Products (3)
Broadcom/BCM5820X
Dell/ControlVault3 < 5.15.14.19
Dell/ControlVault3 Plus < 6.2.36.47
Published Nov 17, 2025
Tracked Since Feb 18, 2026