Home

Description

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

PUBLISHED Reserved 2025-02-11 | Published 2025-08-04 | Updated 2026-02-26 | Assigner dell




HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-321: Use of Hard-coded Cryptographic Key

Product status

Default status
unaffected

Any version before 3.8.1.5
affected

Default status
unaffected

4.0.0.0 (semver) before 4.0.0.0 or later
affected

References

www.dell.com/...rd-coded-ssh-cryptographic-key-vulnerability vendor-advisory

cve.org (CVE-2025-26476)

nvd.nist.gov (CVE-2025-26476)

Download JSON