CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-45378

CVSS 9.1v3.1pub. 2025-11-05upd. 2025-11-07

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is possible through network with known privileged user/password.

🤖 AI Analysis
How it works

An attacker possessing authenticated credentials for a privileged account (login and password) can use the restricted shell available on the Dell CloudLink server to escape its limitations and execute arbitrary system commands. If the SSH service is enabled on the server and configured with web credentials, the attack can be carried out remotely over the network without requiring physical access to the device. After successfully escaping the restricted shell, the attacker can escalate privileges to a higher level on the server.

Impact

An attacker can gain unauthorized access to the CloudLink server's system shell and then escalate privileges and take full control of the system — this includes confidentiality, integrity, and availability of data and services.

Mitigation & patch

Dell CloudLink should be updated to the version indicated by the manufacturer as secure, according to bulletin DSA-2025-374 available at: https://www.dell.com/support/kbdoc/en-us/000384363/. As a temporary measure until patch deployment, it is recommended to disable or restrict access to the SSH service and apply the principle of least privilege for administrative accounts.

Who is affected

Dell CloudLink versions 8.0 to 8.1.2 (inclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Dell Cloudlink

    APP
    Dell
    8.0 – 8.1.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-46364CRITICAL9.1PL ✓same product

Dell CloudLink — CLI Escape umożliwia przejęcie kontroli nad systemem

CVE-2022-34380CRITICAL9.3PL ✓same product

Authentication Bypass w Dell CloudLink — obejście uwierzytelnienia konsoli systemowej

CVE-2022-34379CRITICAL9.4PL ✓same product

Authentication Bypass w Dell EMC CloudLink — logowanie bez hasła

CVE-2021-36312CRITICAL9.1PL ✓same product

Dell EMC CloudLink — zakodowane hasło umożliwiające nieautoryzowany dostęp

CVE-2021-36313CRITICAL9.1PL ✓same product

Command Injection w Dell EMC CloudLink 7.1 i wcześniejszych