Executive brief
Dell PowerFlex Manager, a tool used to manage and automate software-defined storage infrastructure, contains a security weakness in its SSH configuration. A user who already has low-level access to the system could exploit this to bypass certain security protections. This could allow an attacker to circumvent intended restrictions, though it requires existing access and specific conditions to be met.
Technical details
Dell PowerFlex Manager (versions 4.6.2 and prior) is vulnerable to the use of broken or risky cryptographic algorithms within its SSH configuration (CWE-327). The vulnerability allows a low-privileged attacker with local access to the system to potentially bypass security protection mechanisms. Exploitation is considered difficult (High Attack Complexity) as it requires specific conditions to successfully leverage the weak cryptography. Dell has released security updates (DSA-2025-434 and DSA-2025-435) to address this issue across PowerFlex Appliance and Rack configurations.
Affected products
- Dell PowerFlex Manager <=4.6.2
- Dell PowerFlex Rack < 3.7.8.0, < 3.8.3.0
- Dell PowerFlex Appliance Intelligent Catalog < 48.383.00
Timeline
- 2026-05-22: advisory: Initial publication of CVE-2025-46371 and Dell security advisories.
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities