CVE-2025-36591: Medium severity Dell Dell ECS vulnerability
Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell ECSto a version that resolves this vulnerability.Fixed in 3.8.1.7 - Upgrade
Upgrade
Dell ObjectScaleto a version that resolves this vulnerability.Fixed in 4.4.0.0
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Exploitation requires an attacker to already have high privileges and local access to an affected Dell ECS or Dell ObjectScale system. It is not described as remotely exploitable.
What is the potential impact if the vulnerability is exploited?
Successful exploitation could lead to information exposure. The provided data does not indicate an impact on integrity or availability.
Which releases are affected?
Dell ECS versions 3.8.1.0 through 3.8.1.7 are affected. Dell ObjectScale versions earlier than 4.4.0.0 are affected.