CVE-2025-26477
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 17, 2025
CWE ID 20
Summary
CVE-2025-26477 is a newly disclosed vulnerability affecting Dell ECS version 3.8.1.4 and older. This issue involves improper input validation, allowing a remote, low-privileged attacker to potentially exploit it for code execution. This vulnerability poses a significant risk as an attacker could gain unauthorized access and execute malicious code on affected systems. It is recommended that users of Dell ECS update to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Amazon Elastic Container Service
Affected Vendors
- Amazon Web Services