Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Dell Dell storage Manager | |
| Vendors & Products | Dell Dell storage Manager | 
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An unauthenticated remote attacker can access APIs exposed by ApiProxy.war in DataCollectorEar.ear by using a special SessionKey and UserId. These userid are special users created in compellentservicesapi for special purposes. | |
| Weaknesses | CWE-287 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: dell
Published: 2025-10-24T14:09:55.238Z
Updated: 2025-10-25T03:56:07.748Z
Reserved: 2025-04-21T05:03:43.637Z
Link: CVE-2025-43995
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-24T15:15:38.380
Modified: 2025-10-27T13:20:15.637
Link: CVE-2025-43995
 Redhat
                        Redhat
                    No data.