Database/Control plane, storage & DevOps
Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementation
CVSS 6.7CVE-2025-46424Control plane, storage & DevOpscurated
Impact
Use of a cryptographic primitive with a risky implementation, exploitable by a high-privileged attacker for denial of service of the key manager. If CloudLink is down, encrypted volumes do not unlock - this is an availability risk to the storage tier.
Who can reach it
Local high-privilege access on the appliance.
What to do
Upgrade CloudLink to 8.2. Make sure you have tested the KMS-unavailable failure mode for your storage estate.
References
Related entries
- JumpServer: Jinja2 injection in Applet Host fields executes commands on the control nodeCVE-2026-44845 · JumpServer (Applet Host deployment, Jinja2 template injection)Medium
- GlusterFS (glusterd management): An authenticated TLS client can use gluster cli --remote-host to add itself to theCVE-2018-10841 · GlusterFS (glusterd management)Medium
- Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interfaceCVE-2021-0060 · Intel SPS (HECI subsystem compartmentalisation)Medium
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedCVE-2024-38482 · Dell CloudLink (cluster component exception handling)Medium
- AMD Versal Adaptive SoC - PLM runtime services address validation: The Platform Loader and Manager firmware on AMDCVE-2025-0037 · AMD Versal Adaptive SoC - PLM runtime services address validationMedium
- Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manageCVE-2026-84724 · Red Hat Ansible Automation Platform automation-controller (system-job launch, awx-manage argument vector)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.