Dell PowerFlex Manager VM Insertion of Sensitive Information into Log File Vulnerability

Vulnerability

A vulnerability allowing the insertion of sensitive information into log files has been identified in Dell PowerFlex Manager VM versions prior to 4.6.2.1. This vulnerability could be exploited by a low-privileged attacker with remote access, potentially leading to the disclosure of certain user credentials. The exposed credentials might be used to access the system with the privileges of the compromised account.

Impact

Exploitation of this vulnerability could result in the unauthorized disclosure of user credentials, which may be used to access the system with the privileges of the compromised account.

Remediation

Users are advised to upgrade to Dell PowerFlex Manager VM version 4.6.2.1 or later. For assistance, visit the Dell PowerFlex Support page.

Added: Jul 9, 2025, 7:17 PM
Updated: Jul 9, 2025, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.