CVE-2025-36572

Executive Summary

Dell PowerStore 4.0.0.0 contains hard‑coded credentials in its image file. A low‑privileged attacker with remote access who knows these credentials can exploit the flaw to gain unauthorized access, leveraging the privileges of the hard‑coded account. The vulnerability does not require elevated privileges or local access, making it a potential threat for remote attackers.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2025-05-28T17:15:24.093 - Last Modified: 2026-09-11T13:31:10.763

Original Description: Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.

"Simply put, you believer that things or people make you unhappy, but this is not accurate. You make yourself unhappy."

— Wayne Dyer
Source: NVD