Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    01 Aug 2025, 20:55
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Dell Dell elastic Cloud Storage Dell objectscale | |
| References | () https://www.dell.com/support/kbdoc/en-in/000300068/dsa-2025-097-security-update-for-dell-objectscale-4-0-multiple-vulnerabilities - Vendor Advisory | |
| Summary | 
 | |
| CPE | cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* cpe:2.3:a:dell:objectscale:*:*:*:*:*:*:*:* | 
17 Apr 2025, 12:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-17 12:15
Updated : 2025-08-01 20:55
NVD link : CVE-2025-26478
Mitre link : CVE-2025-26478
CVE.ORG link : CVE-2025-26478
JSON object : View
Products Affected
                dell
- objectscale
- elastic_cloud_storage
CWE
                
                    
                        
                        CWE-295
                        
            Improper Certificate Validation
