High severity7.3NVD Advisory· Published Nov 17, 2025· Updated Apr 15, 2026
CVE-2025-36460
CVE-2025-36460
Description
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a WinBioControlUnit call to the StorageAdapter with the ControlCode 2 (WBIO_USH_GET_IDENTITY) with an improper ReceiveBuferSize value.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.