CVE-2025-46371: Medium severity Dell PowerFlex Manager vulnerability
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerFlex Managerto a version that resolves this vulnerability.Fixed in 4.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46371?
The severity of CVE-2025-46371 is low, with a CVSS score of 3.6.
What software is affected by CVE-2025-46371?
CVE-2025-46371 affects Dell PowerFlex Manager versions 4.6.2 and below.
What is the impact of CVE-2025-46371?
CVE-2025-46371 could allow a low privileged attacker with local access to bypass protection mechanisms.
How can I mitigate CVE-2025-46371?
Mitigation for CVE-2025-46371 involves upgrading to a version of Dell PowerFlex Manager that is higher than 4.6.2.
Who can exploit CVE-2025-46371?
A low privileged attacker with local access could potentially exploit CVE-2025-46371.