Cyber Posture

CVE-2025-21102

High

Published: 08 January 2025

Published
08 January 2025
Modified
24 January 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0005 14.7th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-21102 is a high-severity Plaintext Storage of a Password (CWE-256) vulnerability in Dell Vxrail D560 Firmware. Its CVSS base score is 7.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Unsecured Credentials (T1552); ranked at the 14.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 IA-5 (Authenticator Management) and SC-28 (Protection of Information at Rest).

Threat & Defense at a Glance

What attackers do: exploitation maps to Unsecured Credentials (T1552) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

SC-28 requires cryptographic or other protections for sensitive information at rest, directly mitigating plaintext storage of passwords and preventing information exposure.

prevent

IA-5 mandates secure management and storage of authenticators including passwords, commensurate with their sensitivity, preventing unauthorized access to plaintext credentials.

prevent

SI-2 requires timely identification, reporting, and correction of flaws like CVE-2025-21102 through patching, eliminating the plaintext storage vulnerability.

MITRE ATT&CK Enterprise TechniquesAI

T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
Why these techniques?

Direct mapping to insecure plaintext credential storage accessible locally by high-privileged users, enabling credential discovery.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Deeper analysisAI

CVE-2025-21102 is a Plaintext Storage of a Password vulnerability affecting Dell VxRail in versions 7.0.000 through 7.0.532. Published on 2025-01-08, this issue corresponds to CWE-256 (Plaintext Storage of a Password) and CWE-522 (Insufficiently Protected Credentials), with a CVSS v3.1 base score of 7.5 (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

A high-privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. The attack requires local access, high attack complexity, and high privileges, with no user interaction needed; successful exploitation changes scope and results in high impacts to confidentiality, integrity, and availability.

Dell has issued security advisory DSA-2025-027, detailed in KB article 000269793, providing a security update for this and multiple other vulnerabilities in VxRail. Practitioners should review the advisory at https://www.dell.com/support/kbdoc/en-us/000269793/dsa-2025-027-security-update-for-dell-vxrail-for-multiple-vulnerabilities?ref=emcadvisory_000269793_High_null for patching instructions and mitigation guidance.

Details

CWE(s)

Affected Products

dell
vxrail d560 firmware
7.0.000 — 7.0.533
dell
vxrail d560f firmware
7.0.000 — 7.0.533
dell
vxrail e460 firmware
7.0.000 — 7.0.533
dell
vxrail e560 firmware
7.0.000 — 7.0.533
dell
vxrail e560 vcf firmware
7.0.000 — 7.0.533
dell
vxrail e560f firmware
7.0.000 — 7.0.533
dell
vxrail e560f vcf firmware
7.0.000 — 7.0.533
dell
vxrail e560n firmware
7.0.000 — 7.0.533
dell
vxrail e560n vcf firmware
7.0.000 — 7.0.533
dell
vxrail e660 firmware
7.0.000 — 7.0.533
+32 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2025-21111Same product: Dell Vxrail D560
CVE-2026-21417Same vendor: Dell
CVE-2025-36568Same vendor: Dell
CVE-2026-35155Same vendor: Dell
CVE-2024-48831Same vendor: Dell
CVE-2026-23775Same vendor: Dell
CVE-2026-28261Same vendor: Dell
CVE-2026-25907Same vendor: Dell
CVE-2025-24386Same vendor: Dell
CVE-2026-32655Same vendor: Dell

References