Dell ControlVault3 and ControlVault3 Plus Out-of-Bounds Read Vulnerability Allowing Information Leak

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in the cv_send_blockdata function of Dell ControlVault3, prior to versions 5.15.10.14, and Dell ControlVault3 Plus, prior to version 6.2.26.36. This vulnerability can be triggered by a specially crafted ControlVault API call, leading to an information leak.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure.

Remediation

Users can update to Dell ControlVault3 version 5.15.10.14 or later, or Dell ControlVault3 Plus version 6.2.26.36 or later. For specific update instructions, visit the Dell Drivers & Downloads site.

Added: Jun 13, 2025, 9:32 PM
Updated: Jun 13, 2025, 9:32 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.