#VU113792 Out-of-bounds write in ControlVault3 and ControlVault3 Plus - CVE-2025-25050
Published: August 11, 2025
ControlVault3
ControlVault3 Plus
Dell
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the cv_upgrade_sensor_firmware functionality. A local user can use a specially crafted ControlVault API call, trigger an out-of-bounds write and execute arbitrary code on the target system.