CVE-2025-43992

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*

History

16 May 2026, 02:52

Type Values Removed Values Added
CPE cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
First Time Dell
Dell elastic Cloud Storage
Dell objectscale
References () https://www.dell.com/support/kbdoc/en-us/000462117/dsa-2026-047-security-update-for-dell-ecs-and-objectscale-multiple-vulnerabilities-1 - () https://www.dell.com/support/kbdoc/en-us/000462117/dsa-2026-047-security-update-for-dell-ecs-and-objectscale-multiple-vulnerabilities-1 - Vendor Advisory

11 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 10:16

Updated : 2026-05-16 02:52


NVD link : CVE-2025-43992

Mitre link : CVE-2025-43992

CVE.ORG link : CVE-2025-43992


JSON object : View

Products Affected

dell

  • elastic_cloud_storage
  • objectscale
CWE
CWE-302

Authentication Bypass by Assumed-Immutable Data