← Vulnerability feed

Vulnerability record · CVE-2025-43994 · published 24 October 2025

CVE-2025-43994: Dell storage manager missing authentication for critical function vulnerability

Dell · Storage Manager

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

7.5 CVSS 3.1 High EPSS 0.60% · top 53.4% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-43994 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-43995Dell storage manager improper authentication vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…EPSS 0.84%9.8CVE-2017-14374Dell storage manager hard-coded credentials vulnerabilityThe SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with…EPSS 1.3%8.8CVE-2025-22477Dell storage manager improper authentication vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with…EPSS 0.29%8.1CVE-2025-22478Dell storage manager xml external entity (xxe) vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An…EPSS 0.27%8.0CVE-2025-22476Dell storage manager command injection vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command…EPSS 0.55%6.5CVE-2025-46425Dell storage manager xml external entity (xxe) vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A …EPSS 0.33%6.5CVE-2017-14384Dell storage manager path traversal vulnerabilityIn Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote mal…EPSS 1.8%5.2CVE-2025-23379Dell storage manager cross-site scripting vulnerabilityDell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-sit…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-43994), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.