Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
References
Configurations
Configuration 1 (hide)
|
History
14 Jan 2026, 18:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.dell.com/support/kbdoc/en-us/000337554/dsa-2025-235-dell-powermaxos-dell-powermax-eem-dell-unisphere-for-powermax-dell-unisphere-for-powermax-virtual-appliance-dell-unisphere-360-dell-solutions-enabler-and-dell-solutions-enabler-virtual-appliance-security-update-for-multiple-vulnerabilit - Vendor Advisory | |
| CPE | cpe:2.3:a:dell:solutions_enabler_virtual_appliance:*:*:*:*:*:*:*:* cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:* |
|
| First Time |
Dell solutions Enabler Virtual Appliance
Dell Dell unisphere For Powermax Virtual Appliance |
30 Jun 2025, 18:38
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
27 Jun 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-06-27 14:15
Updated : 2026-01-14 18:52
NVD link : CVE-2025-36595
Mitre link : CVE-2025-36595
CVE.ORG link : CVE-2025-36595
JSON object : View
Products Affected
dell
- unisphere_for_powermax_virtual_appliance
- solutions_enabler_virtual_appliance
CWE
CWE-96
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
