CVE-2025-26483 PUBLISHED

Assigner: dell
Reserved: 11.02.2025 Published: 22.05.2026 Updated: 22.05.2026

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor Dell
Product PowerFlex Manager (Appliance)
Versions Default: unaffected
  • affected from 0 to IC 48.378.00 (excl.)
  • affected from 0 to IC 48.383.00 (excl.)
Vendor Dell
Product PowerFlex Manager (Rack)
Versions Default: unaffected
  • affected from 0 to 3.7.8.0 (excl.)
  • affected from 0 to 3.8.3.0 (excl.)
Vendor Dell
Product PowerFlex Manager
Versions Default: unaffected
  • affected from 0 to 4.6.2 (incl.)

References

Problem Types

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') CWE