Use of hard-coded credentials in PowerStoreT OS - CVE-2025-36572
Published: May 27, 2025
Vulnerability identifier: #VU109882
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36572
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in the PowerStore image file. A remote user with access to the system can abuse hard-coded credentials to escalate privileges.
Affected software
PowerStoreT OS
PowerStore 500T
PowerStore 1000T
PowerStore 1200T
PowerStore 3000T
PowerStore 3200Q
PowerStore 3200T
PowerStore 5000T
PowerStore 5200T
PowerStore 7000T
PowerStore 9000T
PowerStore 9200T
PowerStore 500T
PowerStore 1000T
PowerStore 1200T
PowerStore 3000T
PowerStore 3200Q
PowerStore 3200T
PowerStore 5000T
PowerStore 5200T
PowerStore 7000T
PowerStore 9000T
PowerStore 9200T
How to mitigate CVE-2025-36572
Install updates from vendor's website.
PowerStoreT OS - update to 4.0.1.3-2494147