Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking a legitimate user into clicking a specially crafted link, an attacker can send them to a fraudulent site that looks like a real login page. This is primarily used in phishing campaigns to steal sensitive credentials or corporate data.
Technical details
An open redirect vulnerability (CWE-601) exists in Dell PowerFlex Manager versions 4.6.2 and prior. The application fails to properly validate user-supplied input used in redirection targets, allowing an unauthenticated remote attacker to construct a URL that redirects a victim to an arbitrary external domain. Exploitation requires user interaction, typically via a phishing link. Successful exploitation can be used to conduct sophisticated social engineering attacks or to bypass certain security filters that trust the PowerFlex Manager domain. Dell has released security updates (DSA-2025-434 and DSA-2025-435) to address this issue.
Affected products
- Dell PowerFlex Manager <= 4.6.2
- Dell PowerFlex Rack < 3.7.8.0, < 3.8.3.0
- Dell PowerFlex Appliance Intelligent Catalog < 48.383.00
Timeline
- 2026-05-22: advisory: Initial publication of CVE-2025-26483 by Dell and NVD.
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities