Critical Vulnerabilities in Dell Products (CVE-2025-27690, CVE-2025-22398, CVE-2025-24383)

Imechapishwa: Apr 11, 2025 08:53

Advisory No: TZCERT-SA-25-0087

Source: Dell

Software Affected: Dell PowerScale OneFS, Dell Unity

Overview

Dell products are vulnerable to multiple critical vulnerabilities. Exploitation of these vulnerabilities may allow attackers to compromise the affected system.

Description

Dell PowerScale OneFS and Dell Unity are vulnerable to CVE-2025-27690, CVE-2025-22398, and CVE-2025-24383, with CVSS scores of 9.8 and 9.1. Dell PowerScale OneFS contains a use of default password vulnerability; meanwhile, Dell Unity contains an improper neutralization of special Elements used in an OS Command. Exploitation of these vulnerabilities may lead to account takeover and arbitrary code execution on the affected devices.

Impact

Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.

Solution

Dell has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Ripoti Tukio