Vulnerability Description
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powerflex Appliance Intelligent Catalog | < 48.383.00 |
| Dell | Powerflex Manager | <= 4.6.2 |
| Dell | Powerflex Rack | < 3.7.8.0 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-Vendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-Vendor Advisory
FAQ
What is CVE-2025-46371?
CVE-2025-46371 is a vulnerability with a CVSS score of 3.6 (LOW). Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploi...
How severe is CVE-2025-46371?
CVE-2025-46371 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-46371?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Powerflex Appliance Intelligent Catalog, Dell Powerflex Manager, Dell Powerflex Rack.