Skip to main content
Vulnerability Database/CVE-2025-36599

CVE-2025-36599: Dell PowerFlex Manager Information Disclosure

CVE-2025-36599 is an information disclosure vulnerability in Dell PowerFlex Manager that exposes user credentials through log files. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-36599 Overview

CVE-2025-36599 is an Insertion of Sensitive Information into Log File vulnerability [CWE-532] in Dell PowerFlex Manager VM. Versions prior to 4.6.2.1 write user credentials into log files that are accessible to authenticated users. A low-privileged attacker with remote network access can read the exposed credentials from the logs. The attacker can then reuse those credentials to authenticate to the system with the privileges of the compromised account.

Critical Impact

Authenticated remote attackers can retrieve user credentials from PowerFlex Manager log files and reuse them to access the system as the affected user.

Affected Products

  • Dell PowerFlex Manager VM versions prior to 4.6.2.1
  • Dell PowerFlex Manager Platform (PFMP)
  • Dell PowerFlex storage environments managed by vulnerable PFMP instances

Discovery Timeline

  • 2025-07-09 - CVE-2025-36599 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-36599

Vulnerability Analysis

The vulnerability is classified under CWE-532: Insertion of Sensitive Information into Log File. Dell PowerFlex Manager writes sensitive user credential material into log records during normal operation. Because these logs are readable by low-privileged authenticated users, credential content becomes available to anyone with basic access to the management VM.

Exploitation requires network reachability to the PowerFlex Manager VM and a low-privileged account. No user interaction is required. The confidentiality impact is high, while integrity and availability are not directly affected by the primary flaw. However, harvested credentials can be replayed to expand access, which can lead to follow-on integrity and availability impact against the storage management plane.

Root Cause

The root cause is improper handling of sensitive fields during log generation inside the PowerFlex Manager VM. Credential values that should be redacted, masked, or omitted are instead persisted in cleartext within log files. Access controls on those log files do not restrict them exclusively to administrators, allowing a low-privileged user to read them.

Attack Vector

The attack vector is network-based against the PowerFlex Manager management interface. An attacker authenticates with a low-privileged account, then reads log files that contain leaked credential material. The attacker uses the recovered credentials to log in as the affected user, potentially including higher-privileged operators whose secrets were captured while they performed management actions.

No verified public exploit code is available for CVE-2025-36599. Refer to the Dell Security Update DSA-2025-279 for vendor technical details.

Detection Methods for CVE-2025-36599

Indicators of Compromise

  • Unexpected read access to PowerFlex Manager log directories by non-administrative accounts.
  • Successful logins to PowerFlex Manager from user accounts shortly after their credentials appeared in log entries.
  • Repeated access to log files or log-export APIs from a single low-privileged session.
  • Authentications originating from unusual source addresses using valid credentials of PFMP operators.

Detection Strategies

  • Audit PowerFlex Manager log files for the presence of credential-like patterns such as password fields, tokens, or authorization headers.
  • Alert on any non-administrative account that reads, downloads, or copies files from PFMP log paths.
  • Correlate credential appearance in logs with subsequent authentication events from the same account for possible replay.

Monitoring Recommendations

  • Forward PowerFlex Manager audit and access logs to a centralized SIEM for retention and correlation.
  • Monitor authentication events for anomalies such as impossible-travel logins or off-hours access by service accounts.
  • Track configuration and role changes performed in PFMP that follow credential-exposure events.

How to Mitigate CVE-2025-36599

Immediate Actions Required

  • Upgrade Dell PowerFlex Manager VM to version 4.6.2.1 or later as specified in DSA-2025-279.
  • Rotate credentials for all accounts that authenticated to affected PowerFlex Manager instances before the upgrade.
  • Review and purge historical log files that may contain credential material, and restrict who can read them.
  • Restrict network access to the PowerFlex Manager management interface to authorized administrator networks.

Patch Information

Dell released the fix in PowerFlex Manager VM version 4.6.2.1. Full remediation details, affected components, and upgrade guidance are documented in the Dell Security Update DSA-2025-279.

Workarounds

  • Limit PowerFlex Manager access to a small set of trusted administrator accounts until the patch is deployed.
  • Tighten filesystem permissions on log directories so only administrators can read PFMP log files.
  • Enforce multi-factor authentication and rotate any credentials suspected to have appeared in logs.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.