---
id: CVE-2025-43995
title: >-
  Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an
  Improper Authentication vulnerability
summary: >-
  Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an
  Improper Authentication vulnerability. An unauthenticated attacker with remote
  access could potentially exploit this vulnerability, leading to Protection
  mecha…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: dell
product: storage_manager
affected:
  - storage_manager < 2020
  - storage_manager = 2020
patched:
  - storage_manager 2020
published: '2025-10-24'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-43995'
references:
  - url: >-
      https://www.dell.com/support/kbdoc/en-us/000382899/dsa-2025-393-security-update-for-storage-center-dell-storage-manager-vulnerabilities
    label: security_alert@emc.com
tags:
  - nvd
epss: 0.00844
epssPercentile: 0.56392
ingestedAt: '2026-09-30T23:29:32.448Z'
---

## Overview

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

## Affected

- `storage_manager < 2020`
- `storage_manager = 2020`

## Remediation

Upgrade past the affected range:

- `storage_manager 2020`
