Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell powerflex Manager |
|
| CPEs | cpe:2.3:a:dell:powerflex_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell
Dell powerflex Manager |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the system with privileges of the compromised account. | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2025-07-09T19:19:13.688Z
Reserved: 2025-04-15T21:32:11.414Z
Link: CVE-2025-36599
Updated: 2025-07-09T19:19:04.381Z
Status : Analyzed
Published: 2025-07-09T19:15:24.207
Modified: 2026-01-16T15:00:37.263
Link: CVE-2025-36599
No data.
OpenCVE Enrichment
No data.