PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32750 Dell CVE debrief

Published on 2026-05-20, CVE-2025-32750 affects Dell PowerFlex Manager versions 4.6.2 and earlier. NVD rates the issue HIGH with a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating an unauthenticated remote attacker could potentially expose information through directory listing.

Vendor
Dell
Product
PowerFlex Manager (Appliance)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-23
Advisory published
2026-05-20
Advisory updated
2026-07-23

Who should care

Dell PowerFlex Manager administrators, vulnerability management teams, and SOC/IR staff responsible for managing exposed or broadly reachable PowerFlex Manager deployments.

Technical summary

This issue is described as an exposure of information through directory listing (CWE-548) in Dell PowerFlex Manager. The supplied NVD data shows remote, unauthenticated attack conditions with high confidentiality impact and no integrity or availability impact. NVD currently lists the record as 'Awaiting Analysis.'

Defensive priority

High. The issue is remotely reachable, requires no authentication, and can expose sensitive information. Prioritize any PowerFlex Manager deployment at version 4.6.2 or earlier, especially if management interfaces are network-accessible.

Recommended defensive actions

  • Review Dell's security update advisories DSA-2025-434 and DSA-2025-435 and apply Dell-provided remediation for affected PowerFlex deployments.
  • Inventory PowerFlex Manager instances and confirm whether any are running version 4.6.2 or earlier; prioritize those systems for remediation.
  • Restrict network access to PowerFlex Manager management interfaces until the affected systems are updated.
  • Check for unintended directory browsing or exposed files on PowerFlex Manager endpoints and review access logs for suspicious unauthenticated requests.

Evidence notes

The supplied NVD record identifies CVE-2025-32750 as an information exposure issue with CWE-548 and CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The NVD vulnStatus is 'Awaiting Analysis.' Dell advisories referenced by NVD are DSA-2025-434 and DSA-2025-435. The corpus supports Dell as the vendor reference, but affected-version and remediation details should be confirmed directly in the vendor advisories.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32750 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32750

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32750 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32750

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.