CVE-2025-2769

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 1393

Summary

CVE-2025-2769 is a local privilege escalation vulnerability affecting Bdrive NetDrive. This issue arises from the unsecured loading of an OpenSSL configuration file. An attacker must initially gain the ability to execute low-privileged code on the target system to exploit this flaw. Successful exploitation allows the attacker to escalate privileges and execute arbitrary code with SYSTEM level access. The vulnerability, also known as ZDI-CAN-25295, poses a significant risk to affected installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Dell PowerScale OneFS

Affected Vendors

  • Dell Technologies