CVE-2025-43995Critical· 9.8▾ MidnightDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mecha…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.
storage_manager < 2020storage_manager = 2020Upgrade past the affected range:
storage_manager 2020Connected by shared product, vendor, weakness, or advisory.
CVE-2025-46607Medium· 6.6Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability
CVE-2025-46641Medium· 6.6Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability
CVE-2026-81473High· 8.1Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability
CVE-2026-56792Medium· 4.4Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability
CVE-2025-43936High· 8.1Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability
CVE-2026-81237Medium· 6.5Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability