Dell
Dell Storage Manager: vulnerabilities and CVEs
Dell Storage Manager has 10 published vulnerabilities, 3 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months3
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43995 | Critical (9.8) | 0.84% | — | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading… |
| CVE-2025-43994 | High (7.5) | 0.60% | — | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this… |
| CVE-2025-46425 | Medium (6.5) | 0.33% | — | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit… |
| CVE-2025-22476 | High (8) | 0.55% | — | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent… |
| CVE-2025-23379 | Medium (5.2) | 0.25% | — | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent… |
| CVE-2025-22479 | Medium (4.3) | 0.27% | — | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent… |
| CVE-2025-22478 | High (8.1) | 0.27% | — | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could… |
| CVE-2025-22477 | High (8.8) | 0.29% | — | May 6, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability,… |
| CVE-2017-14384 | Medium (6.5) | 1.8% | — | Mar 16, 2018 | In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read… |
| CVE-2017-14374 | Critical (9.8) | 1.3% | — | Dec 6, 2017 | The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S… |
Other products by Dell
Secure Connect Gateway · 135Data Domain Operating System · 99Powerscale Onefs · 98EMC Powerscale Onefs · 84Wyse Management Suite · 70Latitude 9410 Firmware · 65Latitude 5411 Firmware · 64Latitude 5511 Firmware · 64Latitude 7410 Firmware · 63Latitude 7310 Firmware · 63Latitude 5310 Firmware · 62Latitude 5400 Firmware · 62