CVE-2025-46371 PUBLISHED

Assigner: dell
Reserved: 23.04.2025 Published: 22.05.2026 Updated: 22.05.2026

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 3.6

Product Status

Vendor Dell
Product PowerFlex Manager (Appliance)
Versions Default: unaffected
  • affected from 0 to IC 48.378.00 (excl.)
  • affected from 0 to IC 48.383.00 (excl.)
Vendor Dell
Product PowerFlex Manager (Rack)
Versions Default: unaffected
  • affected from 0 to 3.7.8.0 (excl.)
  • affected from 0 to 3.8.3.0 (excl.)
Vendor Dell
Product PowerFlex Manager
Versions Default: unaffected
  • affected from 0 to 4.6.2 (incl.)

References

Problem Types

  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm CWE