CVE-2025-27686

Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*

History

12 Jan 2026, 19:02

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-ao/000302223/dsa-2025-111-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtual-appliance-dell-unisphere-360-dell-solutions-enabler-and-dell-solutions-enabler-virtual-appliance-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-ao/000302223/dsa-2025-111-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtual-appliance-dell-unisphere-360-dell-solutions-enabler-and-dell-solutions-enabler-virtual-appliance-security-update-for-multiple-vulnerabilities - Vendor Advisory
First Time Dell
Dell unisphere For Powermax
CWE NVD-CWE-Other
Summary
  • (es) Dell Unisphere para PowerMax, versiones anteriores a la 10.2.0.9 y versiones anteriores a la 9.2.4.15, presenta una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en una consulta LDAP (inyección LDAP). Un atacante con privilegios elevados y acceso remoto podría explotar esta vulnerabilidad, lo que provocaría una inyección de scripts.
CPE cpe:2.3:a:dell:unisphere_for_powermax:*:*:*:*:*:*:*:*

07 Apr 2025, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-07 14:15

Updated : 2026-01-12 19:02


NVD link : CVE-2025-27686

Mitre link : CVE-2025-27686

CVE.ORG link : CVE-2025-27686


JSON object : View

Products Affected

dell

  • unisphere_for_powermax
CWE
CWE-90

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

NVD-CWE-Other