CVE-2025-36588SQL Injection in Dell Unisphere FOR Powermax

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
0.0%
top 90.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22

Description

Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5dell/unisphere_for_powermaxN/A9.2.4.19
NVDdell/unisphere< 9.2.4.19

🔴Vulnerability Details

2
CVEList
CVE-2025-36588: Dell Unisphere for PowerMax, version(s) 102026-01-22
GHSA
GHSA-xfqp-wv94-qg88: Dell Unisphere for PowerMax, version(s) 102026-01-22
CVE-2025-36588 — SQL Injection in Dell | cvebase