Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27686


Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.


Published

2025-04-07T14:15:24.210

Last Modified

2026-01-12T19:02:51.677

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-90
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell unisphere_for_powermax < 9.2.4.15 Yes
Application dell unisphere_for_powermax < 10.2.0.9 Yes

References