« Volver al listado

CVE-2025-36572

Estado: AnalizadaMedia (6.5)—

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-36572",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-36572",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-28T16:26:23.374062Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "PowerStore",
          "versions": [
            {
              "status": "affected",
              "version": "N/A",
              "lessThan": "4.0.1.3-2494147",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-28T17:15:24.093",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000325205/dsa-2025-223-dell-powerstore-t-security-update-for-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges."
    },
    {
      "lang": "es",
      "value": "Dell PowerStore, versión 4.0.0.0, contiene una vulnerabilidad de uso de credenciales codificadas en el archivo de imagen de PowerStore. Un atacante con pocos privilegios y acceso remoto, conociendo las credenciales codificadas, podría explotar esta vulnerabilidad para obtener acceso no autorizado basándose en los privilegios de la cuenta codificada."
    }
  ],
  "lastModified": "2026-09-11T13:31:10.763",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:powerstoreos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AF49BC0-B632-4C69-93C1-7C763139A0A5",
              "versionEndExcluding": "4.0.1.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:powerstore_1000t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FD5BE2B0-BB56-4E6C-8818-26910B23CE31"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_1200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AB965674-7EBA-437E-A13B-39BC3F3FE139"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_3000t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "861B5BE7-159A-41FF-9658-D243051CAC88"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_3200q:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8456D5B0-3D6A-4020-B693-D949EE2BA12E"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_3200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0A29ED1-5CE6-4D49-A079-7F4E6D782DE1"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_5000t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2D5EE934-AD08-4C2B-B3EA-878975EE825E"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_500t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6B529671-71A1-428C-BC17-C8E002222FEA"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_5200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F0FCFFD4-A989-4AF3-99DF-32AE2547D9C1"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_7000t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "37E8CD6E-65F4-48A0-B796-93E4EE51BD06"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_9000t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D9BB1B88-C9C0-4B08-84C6-279C79E34CD3"
            },
            {
              "criteria": "cpe:2.3:h:dell:powerstore_9200t:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F90EFCBC-F720-4426-8043-EB1489820C22"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}