Dell Technologies has issued a security alert regarding multiple vulnerabilities impacting Dell ObjectScale and Elastic Cloud Storage (ECS) configurations. This includes a significant remote code execution flaw that could enable an unauthenticated attacker to compromise vulnerable systems. Successful exploitation could give an attacker control over the ObjectScale environment, allowing access to data, altering configurations, disrupting storage operations, deploying malicious payloads, or establishing persistence in the affected infrastructure.

Dell ObjectScale provides enterprise-scale object storage, making a compromise significant for organizations storing backups, application data, archives, or cloud-native workloads on the platform. Despite its high attack complexity, the vulnerability does not necessitate credentials or user interaction, thus emphasizing the importance of minimizing network exposure while updates are being implemented.

Two additional flaws impact both Dell ECS versions from 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.4.0.0. The advisory also lists third-party component vulnerabilities related to Apache Log4j, liblzma, and the Linux kernel. Until updates are applied, Dell recommends using Secure Service-Level Communication guidance in the official Security Configuration Guide to mitigate CVE-2025-43936.

Security teams should also restrict administrative and storage-management interfaces to trusted networks, review exposed ObjectScale services, monitor for abnormal authentication activity, and investigate unexpected configuration or permission changes.