← Back to CVE List
CVE-2025-43992NVD
Vulnerability Summary
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.
CVSS v3.1 Base Metrics — Score 5.6 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- Dell Elastic Cloud Storage >= 3.8.1.0 and < 4.3.0.0
- Dell Objectscale < 4.3.0.0
- Dell Elastic Cloud Storage 4.3.0.0
- Dell Objectscale 4.3.0.0