Database/Control plane, storage & DevOps
Dell CloudLink (privilege escalation to database): A privileged user escalates laterally or reads the CloudLink
CVSS 6.7CVE-2025-46366Control plane, storage & DevOpscurated
Impact
A privileged user escalates laterally or reads the CloudLink database directly, obtaining confidential information - which for a KMS means key metadata and policy.
Who can reach it
Local high-privilege access on the appliance.
What to do
Upgrade CloudLink to 8.1.1 or later.
References
Related entries
- Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementationCVE-2025-46424 · Dell CloudLink (risky cryptographic primitive)Medium
- JumpServer: Jinja2 injection in Applet Host fields executes commands on the control nodeCVE-2026-44845 · JumpServer (Applet Host deployment, Jinja2 template injection)Medium
- GlusterFS (glusterd management): An authenticated TLS client can use gluster cli --remote-host to add itself to theCVE-2018-10841 · GlusterFS (glusterd management)Medium
- Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interfaceCVE-2021-0060 · Intel SPS (HECI subsystem compartmentalisation)Medium
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedCVE-2024-38482 · Dell CloudLink (cluster component exception handling)Medium
- AMD Versal Adaptive SoC - PLM runtime services address validation: The Platform Loader and Manager firmware on AMDCVE-2025-0037 · AMD Versal Adaptive SoC - PLM runtime services address validationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.