CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-46608

CVSS 9.1v3.1pub. 2025-11-12upd. 2025-12-05

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity.

🤖 AI Analysis
How it works

An attacker with an account that already has high privileges can remotely, without user interaction, exploit improperly implemented access control in the product. The vulnerability allows bypassing the assigned scope of permissions and escalating them to an even higher level. The vulnerability operates within a changed scope (Scope: Changed), which means its effects may extend beyond the directly attacked system component.

Impact

An attacker can obtain unauthorized access with elevated privileges, which threatens the confidentiality, integrity, and availability of the system and may lead to compromise of customer data stored in the Dell Data Lakehouse environment.

Mitigation & patch

Dell recommends upgrading the product to version 1.6.0.0 or later as soon as possible. Detailed information is available in Dell's security bulletin DSA-2025-375 at: https://www.dell.com/support/kbdoc/en-us/000390529/dsa-2025-375-security-update-for-dell-data-lakehouse-multiple-vulnerabilities

Who is affected

Dell Data Lakehouse in versions prior to 1.6.0.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Dell Data Lakehouse

    APP
    Dell
    < 1.6.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-37143CRITICAL10.0PL ✓same product

Krytyczna podatność RCE w produktach Dell PowerFlex, InsightIQ i Data Lakehouse

CVE-2024-37144HIGH8.2same product

Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior t...

CVE-2025-21110MEDIUM6.7same product

Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerabilit...

CVE-2024-47481MEDIUM6.5same product

Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unaut...

CVE-2024-38302MEDIUM6.8same product

Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in th...