Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
History

Wed, 09 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2025-07-09T18:30:31.566Z

Updated: 2025-07-09T19:19:13.688Z

Reserved: 2025-04-15T21:32:11.414Z

Link: CVE-2025-36599

cve-icon Vulnrichment

Updated: 2025-07-09T19:19:04.381Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-09T19:15:24.207

Modified: 2025-07-10T13:17:30.017

Link: CVE-2025-36599

cve-icon Redhat

No data.