Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18307 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability. |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Jun 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution .An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability. | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability. |
| Title | Dell ControlVault3/ControlVault3 deserialization of untrusted input vulnerability | Dell ControlVault3/ControlVault3 Plus deserialization of untrusted input vulnerability |
Fri, 13 Jun 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution .An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability. | |
| Title | Dell ControlVault3/ControlVault3 deserialization of untrusted input vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2026-02-26T17:50:36.530Z
Reserved: 2025-02-20T15:43:53.955Z
Link: CVE-2025-24919
Updated: 2025-06-17T15:18:19.972Z
Status : Deferred
Published: 2025-06-13T22:15:18.320
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24919
No data.
OpenCVE Enrichment
No data.
EUVD