Database/Control plane, storage & DevOps
Dell CloudLink (CLI escape): A privileged user with a known password escapes the CLI and takes control of the CloudLink
CVE-2025-46364Control plane, storage & DevOpscurated
Impact
A privileged user with a known password escapes the CLI and takes control of the CloudLink server. CloudLink is the key manager for encrypted volumes - control of it is control of the data-at-rest keys for everything it protects.
Who can reach it
Network access plus a known privileged credential.
What to do
Upgrade CloudLink to 8.1.1 or later. Appliance upgrade with a service window. Because this is a KMS, also plan key rotation if you cannot rule out prior access - patching does not undo a key compromise.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.