CVE-2025-32748

EUVD-2025-210272
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
dellpowerflex_rack_release_certification_matrix
𝑥
< 3.8.4.1
dellpowerflex_rack_release_certification_matrix
3.9.0.0 ≤
𝑥
< 3.9.1.1
𝑥
= Vulnerable software versions