CVE-2025-43992

MEDIUM

Dell ECS 3.8.1.0-3.8.1.7 and ObjectScale < 4.3.0.0 - Unauthenticated Authentication Bypass in Geo Replication

Title source: llm
STIX 2.1

Description

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.

Scores

CVSS v3 5.6
EPSS 0.0003
EPSS Percentile 7.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-302
Status published
Products (4)
Dell/ECS < 4.3.0.0 or later
dell/elastic_cloud_storage 3.8.1.0 - 4.3.0.0
dell/objectscale < 4.3.0.0
Dell/ObjectScale < 4.3.0.0 or later
Published May 11, 2026
Tracked Since May 11, 2026