CVE-2025-27686: Medium severity Dell Unisphere for PowerMax vulnerability
Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27686?
CVE-2025-27686 is considered a high-severity vulnerability due to the potential for remote exploitation by privileged attackers.
How do I fix CVE-2025-27686?
To remediate CVE-2025-27686, upgrade Dell Unisphere for PowerMax to version 10.2.0.9 or later, and PowerMax to version 9.2.4.15 or later.
What type of vulnerability is CVE-2025-27686?
CVE-2025-27686 is an LDAP Injection vulnerability resulting from improper neutralization of special elements in an LDAP query.
Who is affected by CVE-2025-27686?
CVE-2025-27686 affects users of Dell Unisphere for PowerMax versions prior to 10.2.0.9 and PowerMax versions prior to 9.2.4.15.
Can CVE-2025-27686 be exploited remotely?
Yes, CVE-2025-27686 can be exploited remotely by an attacker with high privileges.