CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-46364

CVSS 9.1v3.1pub. 2025-11-05upd. 2025-11-07

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system.

🤖 AI Analysis
How it works

The vulnerability (CWE-269 — improper privilege management) consists of the fact that a user with access to the CLI interface and who knows the password can perform a so-called CLI Escape — that is, escape from the restricted shell environment and gain access to the broader operating system. In this way, an attacker bypasses the restrictions imposed on the privileged account and takes control of the system in a scope exceeding the intended permissions.

Impact

An attacker can gain full control over the system, which includes access to sensitive data, the ability to modify configuration, and disruption of services. Due to the scope (Scope: Changed), the impact may affect not only the Dell CloudLink component itself, but also related infrastructure.

Mitigation & patch

Dell CloudLink should be updated to version 8.1.1 or later. Detailed information is available in the manufacturer's security bulletin DSA-2025-374 at: https://www.dell.com/support/kbdoc/en-us/000384363/dsa-2025-374-security-update-for-dell-cloudlink-multiple-security-vulnerabilities

Who is affected

Dell CloudLink in versions earlier than 8.1.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Dell Cloudlink

    APP
    Dell
    < 8.1.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-45378CRITICAL9.1PL ✓same product

Dell CloudLink: command injection przez ucieczkę z restricted shell

CVE-2022-34380CRITICAL9.3PL ✓same product

Authentication Bypass w Dell CloudLink — obejście uwierzytelnienia konsoli systemowej

CVE-2022-34379CRITICAL9.4PL ✓same product

Authentication Bypass w Dell EMC CloudLink — logowanie bez hasła

CVE-2021-36312CRITICAL9.1PL ✓same product

Dell EMC CloudLink — zakodowane hasło umożliwiające nieautoryzowany dostęp

CVE-2021-36313CRITICAL9.1PL ✓same product

Command Injection w Dell EMC CloudLink 7.1 i wcześniejszych