← Vulnerability feed

Vulnerability record · CVE-2025-22476 · published 6 May 2025

CVE-2025-22476: Dell storage manager command injection vulnerability

Dell · Storage Manager

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.

8.0 CVSS 3.1 High EPSS 0.55% · top 56.4% CWE-77 · Command injection
8.0CVSS 3.1 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-22476 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-43995Dell storage manager improper authentication vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…EPSS 0.84%9.8CVE-2017-14374Dell storage manager hard-coded credentials vulnerabilityThe SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with…EPSS 1.3%8.8CVE-2025-22477Dell storage manager improper authentication vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…EPSS 0.29%8.1CVE-2025-22478Dell storage manager xml external entity (xxe) vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An…EPSS 0.27%7.5CVE-2025-43994Dell storage manager missing authentication for critical function vulnerabilityDell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unaut…EPSS 0.60%6.5CVE-2025-46425Dell storage manager xml external entity (xxe) vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A …EPSS 0.33%6.5CVE-2017-14384Dell storage manager path traversal vulnerabilityIn Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote mal…EPSS 1.8%5.2CVE-2025-23379Dell storage manager cross-site scripting vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-sit…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-22476), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.