Description
A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability.
Problem types
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
NA
Any version before 5.15.14.19
Any version before 6.2.36.47
Credits
Discovered by Philippe Laulheret of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2189
www.dell.com/support/kbdoc/en-us/000326061/dsa-2025-228
talosintelligence.com/vulnerability_reports/TALOS-2025-2189