Junglewise Threat Intelligence

CVE-2025-36591: Dell ECS and ObjectScale use of broken cryptographic algorithm

CVE-2025-36591 · Severity: medium · CVSS 4.4 · Published 2026-09-16

Executive brief

Dell ECS and ObjectScale are enterprise storage systems used to store and manage large volumes of data. These versions contain a weak cryptographic algorithm that could allow a local attacker with high privileges to expose sensitive information stored on the system, compromising data confidentiality.

Technical details

The vulnerability is a use of a broken or risky cryptographic algorithm in Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.4.0.0. The attack requires local access and high privilege level on the affected system. Successful exploitation could lead to information disclosure. The fix is available by upgrading to ObjectScale version 4.4.0.0 or later, or ECS version 4.4.0.0 or later.

Affected products

  • Dell Elastic Cloud Storage 3.8.1.0 through 3.8.1.7
  • Dell ObjectScale prior to 4.4.0.0

Timeline

  • 2026-09-16: disclosed

References

Related threats