Description

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.

INFO

Published Date :

2025-10-24T14:09:55.238Z

Last Modified :

2026-02-26T16:57:06.967Z

Source :

dell
AFFECTED PRODUCTS

The following products are affected by CVE-2025-43995 vulnerability.

Vendors Products
Dell
  • Dell Storage Manager
  • Storage Manager
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-43995.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact