Dell ControlVault3 and ControlVault3 Plus Out-of-Bounds Write Vulnerability

Vulnerability

A vulnerability allowing out-of-bounds write has been identified in the cv_upgrade_sensor_firmware function of Dell ControlVault3, versions prior to 5.15.10.14, and Dell ControlVault3 Plus, versions prior to 6.2.26.36. This vulnerability can be triggered by a specially crafted ControlVault API call, potentially leading to memory corruption or other unintended behavior.

Impact

Exploitation of this vulnerability could result in memory corruption, allowing for potential arbitrary code execution or other unintended consequences.

Remediation

Users can update to Dell ControlVault3 version 5.15.10.14 or later, or Dell ControlVault3 Plus version 6.2.26.36 or later. For specific update instructions, visit the Dell Drivers & Downloads site.

Added: Jun 13, 2025, 9:20 PM
Updated: Jun 13, 2025, 9:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.