Description
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Published: 2026-07-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Unisphere for PowerMax, versions 10.3.0.5 and earlier have a flaw, a Deserialization of Untrusted Data vulnerability (CWE‑502), that allows deserialization of untrusted data. If a low-privileged user can reach the Vulnerability endpoint remotely, the attacker can trigger the flaw and run arbitrary commands with system root rights.

Affected Systems

The vulnerability affects Dell Unisphere for PowerMax appliances running version 10.3.0.5 and prior.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% points to a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access by a low‑privileged user who can invoke the deserialization process to gain root privilege.

Generated by OpenCVE AI on July 28, 2026 at 08:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dell Unisphere for PowerMax security update that addresses the deserialization flaw
  • Restrict network access to the Unisphere service so only authorized users can reach it
  • Enforce role‑based access controls to reduce the impact of low‑privileged accounts

Generated by OpenCVE AI on July 28, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unisphere for PowerMax Deserialization Vulnerability Enabling Remote Command Execution with Root Privileges

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Root Command Execution via Untrusted Data Deserialization in Dell Unisphere for PowerMax

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Root Command Execution via Untrusted Data Deserialization in Dell Unisphere for PowerMax

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Deserialization of Untrusted Data in Dell Unisphere for PowerMax Allows Remote Code Execution

Tue, 14 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Deserialization of Untrusted Data in Dell Unisphere for PowerMax Allows Remote Code Execution

Mon, 13 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Deserialization Flaw Enables Remote Command Execution in Dell Unisphere for PowerMax

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Deserialization Flaw Enables Remote Command Execution in Dell Unisphere for PowerMax

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell unisphere For Powermax
Vendors & Products Dell
Dell unisphere For Powermax

Fri, 10 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Unisphere For Powermax
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-14T03:55:41.008Z

Reserved: 2026-06-15T16:28:29.012Z

Link: CVE-2026-54469

cve-icon Vulnrichment

Updated: 2026-07-14T01:40:20.667Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data