Description
An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability.
Problem types
Product status
NA
Any version before 5.15.10.14
Any version before 6.2.26.36
Credits
Discovered by Philippe Laulheret of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2024-2127
www.dell.com/support/kbdoc/en-us/000276106/dsa-2025-053