CVE-2025-32749

MEDIUM

Dell PowerFlex Manager (Appliance) - Incorrect Default Permissions

Title source: rule
STIX 2.1

Description

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 4.0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (5)
Dell/PowerFlex Manager < 4.6.2
Dell/PowerFlex Manager (Appliance) < IC 48.378.00
Dell/PowerFlex Manager (Appliance) < IC 48.383.00
Dell/PowerFlex Manager (Rack) < 3.7.8.0
Dell/PowerFlex Manager (Rack) < 3.8.3.0
Published May 22, 2026
Tracked Since May 22, 2026