CVE-2025-27686: Dell Unisphere For Powermax

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

Affected products

  • Dell Unisphere For Powermax: before 9.2.4.15 (fixed in 9.2.4.15); from 10.0.0, before 10.2.0.9 (fixed in 10.2.0.9)

Published 2025-04-07. Last modified 2026-06-17.