216.73.216.36

CVE-2025-45378

· Published 05/11/2025 17:15 · Modified 07/11/2025 17:52

Labels: CVE-2025-45378 2025-11-05CVE-2025-45378CWE-78[email protected]

Essential information

Published
05/11/2025 17:15
Modified
07/11/2025 17:52
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is possible through network with known privileged user/password.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dell / cloudlink cpe:2.3:a:dell:cloudlink:*:*:*:*:*:*:*:*

References