CVE-2025-45378: OS Command Injection
Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system.
If ssh is enabled with web credentials of server, attack is possible through network with known privileged user/password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45378?
CVE-2025-45378 is classified as a high severity vulnerability allowing unauthorized access and privilege escalation.
How do I fix CVE-2025-45378?
To fix CVE-2025-45378, update your Dell CloudLink installation to the latest version available beyond 8.1.2.
Who is affected by CVE-2025-45378?
CVE-2025-45378 affects users of Dell CloudLink versions 8.0 through 8.1.2.
What are the risks associated with CVE-2025-45378?
The risks associated with CVE-2025-45378 include unauthorized access to the command shell and potential privilege escalation on the CloudLink server.
Is there a workaround for CVE-2025-45378?
A temporary workaround for CVE-2025-45378 includes disabling SSH access if it is not required until a patch can be applied.