First published: Thu Apr 17 2025(Updated: )
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Elastic Cloud Storage | <3.8.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-26478 is considered to be high due to the potential for information disclosure by unauthenticated attackers.
To fix CVE-2025-26478, update Dell ECS to version 3.8.1.5 or later to ensure proper certificate validation.
Users of Dell ECS version 3.8.1.4 and earlier are affected by CVE-2025-26478.
CVE-2025-26478 is classified as an Improper Certificate Validation vulnerability.
No, an attacker needs adjacent network access to exploit CVE-2025-26478.