---
id: CVE-2025-32748
title: >-
  Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header
  Injection vulnerability
summary: >-
  Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header
  Injection vulnerability. An unauthenticated attacker with remote access could
  potentially exploit this vulnerability to trigger redirections.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-601
vendor: dell
product: powerflex_rack_release_certification_matrix
affected:
  - powerflex_rack_release_certification_matrix < 3.8.4.1
  - 'powerflex_rack_release_certification_matrix >= 3.9.0.0, < 3.9.1.1'
patched:
  - powerflex_rack_release_certification_matrix 3.9.1.1
published: '2026-06-17'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-32748'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000059672/ifgroup-not-working-correctly-when-ip-range-is-used
    label: security_alert@emc.com
tags:
  - nvd
epss: 0.00146
epssPercentile: 0.03223
ingestedAt: '2026-09-30T21:25:07.786Z'
---

## Overview

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.

## Affected

- `powerflex_rack_release_certification_matrix < 3.8.4.1`
- `powerflex_rack_release_certification_matrix >= 3.9.0.0, < 3.9.1.1`

## Remediation

Upgrade past the affected range:

- `powerflex_rack_release_certification_matrix 3.9.1.1`
