CVE-2025-26332

8.8

Dell · XtremIO X2

Dell XtremIO X2 contains a vulnerability involving the insertion of sensitive information into log files, which may allow low privileged local attackers to gain unauthorized access.

Executive summary

A vulnerability in Dell XtremIO X2 allows low privileged local attackers to access sensitive credentials within log files, potentially leading to full system compromise.

Vulnerability

This is an insertion of sensitive information into log files (CWE-532). A low privileged attacker with local access can exploit this flaw to retrieve sensitive credentials, which may subsequently be used to gain unauthorized access to the application with the privileges of the compromised account.

Business impact

The potential for information exposure of sensitive credentials poses a significant risk to the confidentiality, integrity, and availability of the affected storage systems. With a CVSS score of 8.8, this vulnerability is categorized as High, reflecting the potential for an attacker to escalate privileges and achieve full system control. Unauthorized access to storage management infrastructure can lead to data breaches, loss of administrative control, and severe operational disruption.

Remediation

Immediate Action: Administrators must update the Dell XtremIO X2 software to the version specified in the vendor security advisory DSA-2025-108.

Proactive Monitoring: Review system access logs for any unauthorized attempts to read or export log files, particularly by low privileged service accounts.

Compensating Controls: Restrict local access to the system to only authorized personnel and ensure that log file permissions are strictly configured to prevent unauthorized reading.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for total system impact, immediate action is required to patch the affected XtremIO X2 units. Organizations should prioritize the update process and restrict local access to the management interface as a primary defense-in-depth measure until the patch is successfully applied.

More Dell CVEs

Sources