ID:12046 - Exploit for Improper Authentication in Dell Storage Manager - CVE-2025-43995

 
Main Vulnerability Database Exploits ID:12046 - Exploit for Improper Authentication in Dell Storage Manager - CVE-2025-43995

ID:12046 - Exploit for Improper Authentication in Dell Storage Manager - CVE-2025-43995

Published: October 27, 2025


Vulnerability identifier: #VU117668
Vulnerability risk: High
CVE-ID: CVE-2025-43995
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
Dell Storage Manager

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can use a special SessionKey and UserId and access APIs exposed by ApiProxy.war in DataCollectorEar.ear.


Remediation

Install updates from vendor's website.