CVE-2025-26483

high
Published 2026-05-22 · Modified 2026-05-22
CVSS v3
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
CVSS v2
VIR risk
8.2

Description

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information.

Predictions

Exploit likelihood
88%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security_alert@emc.com — https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities

vendor Authored 2026-05-27

Vendor advisory: security_alert@emc.com — https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities

Application impact

VendorProductVersionsFixed
dell dellpowerflex_appliance_intelligent_catalog{"endExcluding":"48.383.00"}48.383.00
dell dellpowerflex_manager{"endIncluding":"4.6.2"}
dell dellpowerflex_rack{"endExcluding":"3.7.8.0"}3.7.8.0

References

CWEs

CWE-601

Verify integrity in audit chain (admin only). AS-IS.