CVE-2025-36595Static Code Injection in Dell Unisphere FOR Powermax Vapp

Severity
7.2HIGHNVD
EPSS
0.2%
top 52.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27

Description

Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

CVEListV5dell/unisphere_for_powermax_vappNA9.2.4.17
NVDdell/unisphere9.2.4.09.2.4.17

🔴Vulnerability Details

2
GHSA
GHSA-7886-36j3-hr33: Dell Unisphere for PowerMax vApp, version(s) 92025-06-27
CVEList
CVE-2025-36595: Dell Unisphere for PowerMax vApp, version(s) 92025-06-27
CVE-2025-36595 — Static Code Injection in Dell | cvebase