Impact
Dell Container Storage Modules (csi-powerstore, csi-unity, csi-powerflex, csi-powermax) are affected by an OS Command Injection flaw (CWE-78). The vulnerability allows a high privileged attacker with remote access to inject and execute arbitrary operating system commands on the module. This can compromise the confidentiality, integrity, and availability of the underlying storage infrastructure and any data it hosts.
Affected Systems
The affected products are Dell Container Storage Modules running version csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, and csi-powermax v2.16.0. The exact versions are limited to these releases; other versions are not listed as impacted.
Risk and Exploitability
The vulnerability scores a CVSS of 8, indicating a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog description, the likely attack vector is a remote attacker with high privileges; the attacker could gain remote command execution if the modules are exposed over a network.
OpenCVE Enrichment