CVE-2025-26477

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 17, 2025
CWE ID 20

Summary

CVE-2025-26477 is a newly disclosed vulnerability affecting Dell ECS version 3.8.1.4 and older. This issue involves improper input validation, allowing a remote, low-privileged attacker to potentially exploit it for code execution. This vulnerability poses a significant risk as an attacker could gain unauthorized access and execute malicious code on affected systems. It is recommended that users of Dell ECS update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Amazon Elastic Container Service

Affected Vendors

  • Amazon Web Services