Back

HIGH

Dell ControlVault3/ControlVault3 Plus cv_close arbitrary free vulnerability

Published Jun 13, 2025

Description

An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Jun 13, 2025
Updated Nov 3, 2025
Reserved Feb 6, 2025
CISA Vulnrichment
Updated Jun 17, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a