CVE-2025-43995: Critical severity Dell Storage Manager vulnerability
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43995?
CVE-2025-43995 is classified as a high severity vulnerability due to the improper authentication that allows unauthenticated attackers to bypass security mechanisms.
How do I fix CVE-2025-43995?
To mitigate CVE-2025-43995, update Dell Storage Manager to version 20.1.22 or later as recommended in the security advisory.
What can an attacker do with CVE-2025-43995?
An attacker exploiting CVE-2025-43995 could potentially bypass authentication, gaining unauthorized access to the system remotely.
Which products are affected by CVE-2025-43995?
CVE-2025-43995 affects Dell Storage Center and Dell Storage Manager, version 20.1.21.
Is there a workaround for CVE-2025-43995 if I can't update immediately?
Currently, no specific workaround is recommended for CVE-2025-43995, and it is strongly advised to apply the update as soon as possible.