CVE-2025-26478: Medium severity dell emc elastic cloud storage vulnerability
Published Apr 17, 2025
·Updated
Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Affected Software
3 affected components
Dell ECS<3.8.1.4
Dell Elastic Cloud Storage<=3.8.1.4
Dell ObjectScale<4.0.0.0
Event History
Apr 17, 2025
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26478?
The severity of CVE-2025-26478 is considered to be high due to the potential for information disclosure by unauthenticated attackers.
2
How do I fix CVE-2025-26478?
To fix CVE-2025-26478, update Dell ECS to version 3.8.1.5 or later to ensure proper certificate validation.
3
Who is affected by CVE-2025-26478?
Users of Dell ECS version 3.8.1.4 and earlier are affected by CVE-2025-26478.
4
What type of vulnerability is CVE-2025-26478?
CVE-2025-26478 is classified as an Improper Certificate Validation vulnerability.
5
Can an attacker exploit CVE-2025-26478 remotely?
No, an attacker needs adjacent network access to exploit CVE-2025-26478.