PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32748 Dell CVE debrief

CVE-2025-32748 is a medium-severity vulnerability in Dell PowerFlex rack, versions RCM 3.7/3.7. An unauthenticated attacker with remote access could potentially exploit this Host Header Injection vulnerability to trigger redirections. Organizations using affected versions should review and update their systems to mitigate potential risks. The CVSS score for this vulnerability is 4.3, indicating a medium severity level. Dell has provided a knowledge base article [ref-4] discussing related issues. The CVE was published on June 17, 2026, and last modified on the same day.

Vendor
Dell
Product
PowerFlex rack
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-07-09
Advisory published
2026-06-17
Advisory updated
2026-07-09

Who should care

Administrators and security teams responsible for Dell PowerFlex rack systems, particularly those using versions RCM 3.7/3.7, should be aware of this vulnerability and take necessary precautions to prevent exploitation.

Technical summary

The CVE-2025-32748 vulnerability is classified as a Host Header Injection issue in Dell PowerFlex rack, versions RCM 3.7/3.7. This vulnerability has a CVSS score of 4.3 and a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N. It allows an unauthenticated attacker with remote access to potentially exploit this vulnerability to trigger redirections. The weakness associated with this vulnerability is CWE-601.

Defensive priority

medium

Recommended defensive actions

  • Review and update Dell PowerFlex rack systems to ensure they are not using vulnerable versions RCM 3.7/3.7.
  • Implement proper input validation and sanitization for host headers.
  • Monitor systems for unusual redirection activity.
  • Restrict access to Dell PowerFlex rack systems to only necessary personnel.
  • Regularly review and apply security patches and updates provided by Dell.
  • Consider implementing a web application firewall (WAF) to detect and prevent exploitation attempts.

Evidence notes

The information provided is based on data from official sources, including the CVE.org record [cve-org] and the NVD detail page [nvd]. A reference to a Dell support article [ref-4] is also available, discussing related issues. The vendor information is currently marked as 'Unknown Vendor' with low confidence, though there is evidence suggesting the vendor may be Dell.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32748 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32748

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32748 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32748

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.dell.com/support/kbdoc/en-us/000059672/ifgroup-not-working-correctly-when-ip-range-is-used

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.