Main
Vulnerability Database
Exploits
ID:12046 - Exploit for Improper Authentication in Dell Storage Manager - CVE-2025-43995
ID:12046 - Exploit for Improper Authentication in Dell Storage Manager - CVE-2025-43995
Published: October 27, 2025
Vulnerability identifier: #VU117668
Vulnerability risk: High
CVE-ID: CVE-2025-43995
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
Dell Storage Manager
Dell Storage Manager
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can use a special SessionKey and UserId and access APIs exposed by ApiProxy.war in DataCollectorEar.ear.
Remediation
Install updates from vendor's website.