CVE-2025-43995 is a critical Improper Authentication vulnerability affecting Dell Storage Manager versions 20.1.21. An unauthenticated remote attacker can bypass authentication in the DSM Data Collector by leveraging a special SessionKey and UserId to access exposed APIs, leading to a protection mechanism bypass. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020CPE matchmatch criteria | cpe:2.3:a:dell:storage_manager:*:*:*:*:*:*:*:* | ||
2020CPE matchmatch criteria | cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:* | ||
2020CPE matchmatch criteria | cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:* | ||
2020CPE matchmatch criteria | cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:* | ||
2020CPE matchmatch criteria | cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Dell Storage Manager Multiple Vulnerabilities
Oct 24, 2025Dell Storage Manager Multiple Vulnerabilities
Oct 24, 2025Dell Storage Manager Multiple Vulnerabilities
Oct 24, 2025Dell Storage Manager Multiple Vulnerabilities
Oct 24, 2025Dell Storage Manager Multiple Vulnerabilities
Oct 24, 2025Dell Storage Manager Multiple Vulnerabilities
Oct 24, 2025