CVE-2025-46603

7.0

Dell · CloudBoost Virtual Appliance

Dell CloudBoost Virtual Appliance contains an improper restriction of authentication attempts, allowing an unauthenticated remote attacker to potentially gain unauthorized access.

Executive summary

A critical authentication vulnerability in Dell CloudBoost Virtual Appliance allows unauthenticated remote attackers to bypass security controls and gain unauthorized access to the system.

Vulnerability

The vulnerability, classified as CWE-307, involves an improper restriction of excessive authentication attempts. This flaw allows an unauthenticated attacker with remote access to potentially bypass authentication mechanisms or brute-force credentials, resulting in unauthorized system access.

Business impact

The exploitation of this vulnerability poses a significant risk to data confidentiality, integrity, and availability. By gaining unauthorized access, an attacker could potentially manipulate system configurations, access sensitive backup data, or cause service disruptions, which justifies the high CVSS score of 7.0.

Remediation

Immediate Action: Upgrade the Dell CloudBoost Virtual Appliance to version 19.13.0.2 or later as specified in the official Dell security advisory.

Proactive Monitoring: Monitor authentication logs for an unusual volume of failed login attempts or irregular access patterns originating from unknown or external IP addresses.

Compensating Controls: Ensure the appliance is not directly exposed to the public internet and utilize network segmentation or a VPN to restrict access to authorized management networks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability represents a significant risk to the security of the backup infrastructure. Administrators are urged to prioritize the update to version 19.13.0.2 to remediate the authentication flaw. Failure to apply this update leaves the appliance susceptible to unauthorized remote access and potential compromise of critical data assets.

More Dell CVEs

Sources