CVE-2025-30105 Details
Description
Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
A vulnerability allowing the insertion of sensitive information into log files has been identified in Dell XtremIO versions 6.4.0-22. This issue could be exploited by a low-privileged attacker with local access, potentially leading to unauthorized information exposure. The exposed credentials might be used to access the vulnerable application with the privileges of the compromised account.
Users are advised to upgrade to version 6.4.3 or later. For Dell XtremIO X2 TechAdvisor users, version 3.4 is recommended. Contact Dell customer support for the upgrade.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dell.com/support/kbdoc/en-us/000337241/dsa-2025-108-security-update-for-dell-emc-xtremio-x2 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell techadvisor | >= 2.6, < 3.4 |
CPE
Remediation
| |
| dell xtremio management server | < 6.4.3 |
CPE
Remediation
| |
| dell xtremio x2 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Jul 30, 2025 | New CVE Received | [email protected] |