Dell ECS是美国戴尔(Dell)公司的一款可扩展、易于管理且具有弹性的企业级对象存储解决方案。 Dell ECS 3.8.1.0版本至3.8.1.7版本和Dell ObjectScale 4.3.0.0之前版本存在安全漏洞,该漏洞源于Geo复制中存在假设不可变数据的认证绕过,可能导致未经身份验证的远程攻击者未授权访问传输中的数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dell | ECS | < 4.3.0.0 or later |
affected |
| Dell | ObjectScale | < 4.3.0.0 or later |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dell | ECS | 0 ~ 4.3.0.0 or later | - |
|
| Dell | ObjectScale | 0 ~ 4.3.0.0 or later | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40636 | 9.8 CRITICAL | Dell ECS和Dell ObjectScale 信任管理问题漏洞 |
| CVE-2026-32658 | 8.0 HIGH | Dell Automation Platform 安全漏洞 |
| CVE-2026-26946 | 6.7 MEDIUM | Dell ECS 安全漏洞 |
| CVE-2026-35157 | 5.8 MEDIUM | Dell ECS和Dell ObjectScale 安全漏洞 |
No comments yet