CVE-2025-26476

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:objectscale:4.0.0.0:*:*:*:*:*:*:*

History

14 Jan 2026, 18:00

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000339134/dsa-2025-154-security-update-for-dell-ecs-and-objectscale-use-of-hard-coded-ssh-cryptographic-key-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000339134/dsa-2025-154-security-update-for-dell-ecs-and-objectscale-use-of-hard-coded-ssh-cryptographic-key-vulnerability - Vendor Advisory
CWE CWE-798
CPE cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:objectscale:4.0.0.0:*:*:*:*:*:*:*
First Time Dell objectscale
Dell elastic Cloud Storage
Dell

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) Las versiones de Dell ECS anteriores a la 3.8.1.5/ObjectScale 4.0.0.0 contienen una vulnerabilidad de uso de clave criptográfica codificada. Un atacante no autenticado con acceso local podría explotar esta vulnerabilidad, lo que provocaría un acceso no autorizado.

04 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 19:15

Updated : 2026-01-14 18:00


NVD link : CVE-2025-26476

Mitre link : CVE-2025-26476

CVE.ORG link : CVE-2025-26476


JSON object : View

Products Affected

dell

  • elastic_cloud_storage
  • objectscale
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials