CVE-2025-43992
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data in transit.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.24%
- CWE
- CWE-302
- Published
- 2026-05-11
- Last modified
- 2026-05-12
Affected products
- Dell ECS
- Dell ObjectScale
Weakness type
Related vulnerabilities
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2026-13267 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt
- CVE-2026-50528 — .NET Security Feature Bypass Vulnerability
- CVE-2026-47303 — ASP.NET Core Elevation of Privilege Vulnerability
- CVE-2026-48117 — DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-34460 — NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping