Dell TechnologiesCVE-2025-43936
Dell Technologies ObjectScale: improper authentication
High8.1CVE-2025-43936 · Published Sep 16, 2026 · updated Sep 21, 2026
Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ObjectScale Product | < 4.4.0.0 or later | 4.4.0.0 or later |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More Dell Technologies advisories
All Dell Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Dell Technologies Update Package Framework: stack buffer overflow | Medium6.5 | 26.07.03 or later |
| Sep 16 | Dell Technologies Repository Manager: insecure permissions | High8.5 | 3.5.2 or later |
| Sep 16 | Dell Update Package Framework | High8.2 | 26.07.03 or later |
| Sep 16 | Dell Technologies Update Package Framework: link following | Low3.0 | 26.07.03 or later |
| Sep 16 | Dell Technologies Update Package Framework: link following | Low3.0 | 26.07.03 or later |
| Sep 16 | Dell Technologies Update Package Framework: command injection | High7.3 | 26.07.03 or later |