Database/Control plane, storage & DevOps
Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementation
CVE-2025-46424Control plane, storage & DevOpscurated
Impact
Use of a cryptographic primitive with a risky implementation, exploitable by a high-privileged attacker for denial of service of the key manager. If CloudLink is down, encrypted volumes do not unlock - this is an availability risk to the storage tier.
Who can reach it
Local high-privilege access on the appliance.
What to do
Upgrade CloudLink to 8.2. Make sure you have tested the KMS-unavailable failure mode for your storage estate.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.