Cyber Posture

CVE-2025-21111

High

Published: 08 January 2025

Published
08 January 2025
Modified
24 January 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0005 13.9th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Security Summary

CVE-2025-21111 is a Plaintext Storage of a Password vulnerability affecting Dell VxRail systems in versions 8.0.000 through 8.0.311. This flaw, mapped to CWE-256 (Plaintext Storage of a Password) and CWE-522 (Insufficiently Protected Credentials), involves the insecure storage of sensitive credentials in plaintext within the affected component.

A high-privileged attacker with local access could potentially exploit this vulnerability, as indicated by its CVSS v3.1 base score of 7.5 (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). Successful exploitation would lead to information exposure, with high impacts on confidentiality, integrity, and availability in a scoped attack scenario.

Dell has issued DSA-2025-025, a security update addressing multiple vulnerabilities in VxRail, including CVE-2025-21111. Practitioners should refer to the advisory at https://www.dell.com/support/kbdoc/en-us/000269958/dsa-2025-025-security-update-for-dell-vxrail-for-multiple-vulnerabilities for details on patches and mitigation steps.

Details

CWE(s)
CWE-256CWE-522

Affected Products

dell
vxrail d560 firmware
8.0.000 — 8.320
dell
vxrail d560f firmware
8.0.000 — 8.320
dell
vxrail e460 firmware
8.0.000 — 8.320
dell
vxrail e560 firmware
8.0.000 — 8.320
dell
vxrail e560 vcf firmware
8.0.000 — 8.320
dell
vxrail e560f firmware
8.0.000 — 8.320
dell
vxrail e560f vcf firmware
8.0.000 — 8.320
dell
vxrail e560n firmware
8.0.000 — 8.320
dell
vxrail e560n vcf firmware
8.0.000 — 8.320
dell
vxrail e660 firmware
8.0.000 — 8.320
+32 more product configuration(s) — see NVD for full list

References