Description
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.
Published: 2026-07-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Unisphere for PowerMax contains a path traversal flaw that permits a low‑privileged attacker with remote access to read arbitrary data, such as configuration files or logs, through unauthorized file reads.

Affected Systems

Dell Unisphere for PowerMax versions 10.3.0.5 and earlier are impacted. These installations process remote file path requests without proper validation, enabling unintended file access.

Risk and Exploitability

The likely attack vector is remote access to the Unisphere interface. The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% shows a very low current likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker with low‑privileged remote access to the Unisphere interface can craft a file path to read files on the underlying host; no elevated system privileges are required, and the issue is exploitable only where the Unisphere service is exposed to network traffic.

Generated by OpenCVE AI on July 26, 2026 at 13:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Dell vendor update or security patch that addresses the path traversal flaw in Unisphere for PowerMax 10.3.0.5 and earlier.
  • Limit remote access to the Unisphere web interface to trusted administrators, using network segmentation or VPNs and enforce multi‑factor authentication.
  • Review and tighten file permissions on the underlying host to prevent world‑readable access to sensitive files, and monitor audit logs for unauthorized read attempts.

Generated by OpenCVE AI on July 26, 2026 at 13:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Client‑Side Path Traversal Allowing Arbitrary File Reads in Dell Unisphere for PowerMax

Wed, 22 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell Unisphere for PowerMax Allows Remote File Read

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell Unisphere for PowerMax Allows Remote File Read

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Dell Unisphere for PowerMax Allows Low‑Privilege File Disclosure

Mon, 13 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Dell Unisphere for PowerMax Allows Low‑Privilege File Disclosure

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unisphere for PowerMax Path Traversal Enabling Read of Arbitrary Files

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unisphere for PowerMax Path Traversal Enabling Read of Arbitrary Files

Fri, 10 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell unisphere For Powermax
Vendors & Products Dell
Dell unisphere For Powermax

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Unisphere For Powermax
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-10T18:53:01.001Z

Reserved: 2026-06-15T16:28:29.012Z

Link: CVE-2026-54468

cve-icon Vulnrichment

Updated: 2026-07-10T18:52:57.155Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T14:00:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')