Description
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
Published: 2026-08-06
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a CWE‑200 Sensitive Information Disclosure in Dell Virtual Storage Integrator for VMware vSphere Client. An unauthenticated remote attacker could gain access to active session credentials, permitting the attacker to fully impersonate authenticated users, including administrators. The potential impact is a loss of confidentiality, integrity, and availability across the virtual storage environment, with the ability to conduct arbitrary administrative actions.

Affected Systems

The affected product is Dell Virtual Storage Integrator for VMware vSphere Client from Dell. Versions prior to 10.11.1.0 are impacted. No other vendor or product is listed.

Risk and Exploitability

The CVSS score is 9.1, indicating a critical severity. The EPSS score is not available, but the vulnerability was deemed critical enough that Dell recommends immediate upgrade. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an unauthenticated attacker can exploit this remotely, likely over the vSphere Client network interface, to obtain session credentials.

Generated by OpenCVE AI on August 6, 2026 at 15:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell Virtual Storage Integrator for VMware vSphere Client to version 10.11.1.0 or later.
  • If an immediate upgrade is not possible, limit network access to the vSphere Client or disable remote access to the tool.
  • Monitor session logs for anomalous activity and investigate any unexplained session hijacking attempts.

Generated by OpenCVE AI on August 6, 2026 at 15:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure Leading to Session Hijacking in Dell Virtual Storage Integrator

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-06T13:54:56.399Z

Reserved: 2026-06-15T17:49:28.560Z

Link: CVE-2026-54489

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:45:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor