Description
An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this vulnerability.
Problem types
Product status
NA
Any version before 5.15.10.14
Any version before 6.2.26.36
Credits
Discovered by Philippe Laulheret of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2137
www.dell.com/support/kbdoc/en-us/000276106/dsa-2025-053