CVE-2025-32748

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:powerflex_rack_release_certification_matrix:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:powerflex_rack_release_certification_matrix:*:*:*:*:*:*:*:*

History

09 Jul 2026, 16:40

Type Values Removed Values Added
CPE cpe:2.3:a:dell:powerflex_rack_release_certification_matrix:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000059672/ifgroup-not-working-correctly-when-ip-range-is-used - () https://www.dell.com/support/kbdoc/en-us/000059672/ifgroup-not-working-correctly-when-ip-range-is-used - Broken Link
First Time Dell powerflex Rack Release Certification Matrix
Dell

25 Jun 2026, 14:16

Type Values Removed Values Added
Summary (en) Dell PowerFlex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections. (en) Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.

17 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 17:16

Updated : 2026-07-09 16:40


NVD link : CVE-2025-32748

Mitre link : CVE-2025-32748

CVE.ORG link : CVE-2025-32748


JSON object : View

Products Affected

dell

  • powerflex_rack_release_certification_matrix
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')