Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
History

Fri, 16 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerflex Manager
CPEs cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell powerflex Manager

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}

epss

{'score': 0.0003}


Wed, 09 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-07-09T19:19:13.688Z

Reserved: 2025-04-15T21:32:11.414Z

Link: CVE-2025-36599

cve-icon Vulnrichment

Updated: 2025-07-09T19:19:04.381Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-09T19:15:24.207

Modified: 2026-01-16T15:00:37.263

Link: CVE-2025-36599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.