Use of hard-coded credentials in PowerStoreT OS - CVE-2025-36572

 

Use of hard-coded credentials in PowerStoreT OS - CVE-2025-36572

Published: May 27, 2025


Vulnerability identifier: #VU109882
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-36572
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to presence of hard-coded credentials in the PowerStore image file. A remote user with access to the system can abuse hard-coded credentials to escalate privileges.


Affected software

PowerStoreT OS
PowerStore 500T
PowerStore 1000T
PowerStore 1200T
PowerStore 3000T
PowerStore 3200Q
PowerStore 3200T
PowerStore 5000T
PowerStore 5200T
PowerStore 7000T
PowerStore 9000T
PowerStore 9200T

How to mitigate CVE-2025-36572

Install updates from vendor's website.

PowerStoreT OS - update to 4.0.1.3-2494147

External References

Related Security Bulletins