Description
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.
Published: 2026-07-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerFlex Manager versions older than 5.1.0.1 contain an Improper Neutralization of Special Elements used in an SQL Command (CWE‑‑privileged attacker who can reach the manager remotely to inject malicious SQL statements, enabling the attacker to extract sensitive data and gain unauthorized access to the system.

Affected Systems

All Dell PowerFlex Manager instances running versions earlier than 5.1.0.1 are affected; no specific sub‑versions are listed beyond the cutoff.

Risk and Exploitability

The vulnerability is assigned a CVSS score of 8.5, indicating high severity, while the EPSS score is below 1%, suggesting that widespread exploitation has not yet been observed. The flaw is not yet cataloged in the CISA KEV list. Because the attack can be performed remotely with only low privileges and requires network reachability to the management interface, the risk to confidentiality and integrity remains significant for exposed environments.

Generated by OpenCVE AI on July 28, 2026 at 08:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell PowerFlex Manager to version 5.1.0.1 or later to eliminate the SQL injection flaw.
  • Limit remote access to the management interface by configuring firewall rules to allow traffic only from trusted administrator IP addresses.
  • Enforce strong authentication, segment the PowerFlex Manager from untrusted networks, and monitor for anomalous database queries or login attempts.

Generated by OpenCVE AI on July 28, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell PowerFlex Manager (pre‑5.1.0.1)

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell PowerFlex Manager (pre‑5.1.0.1)

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager (v<5.1.0.1) Enables Remote Low‑Privileged Data Theft

Wed, 15 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager (v<5.1.0.1) Enables Remote Low‑Privileged Data Theft

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager Pre‑5.1.0.1 Allowing Remote Information Disclosure

Mon, 13 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager Pre‑5.1.0.1 Allowing Remote Information Disclosure

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager Enables Remote Information Disclosure and Unauthorized Access

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Dell PowerFlex Manager Enables Remote Information Disclosure and Unauthorized Access

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerflex Manager
Vendors & Products Dell
Dell powerflex Manager

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Dell Powerflex Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-10T13:14:31.666Z

Reserved: 2026-06-22T17:04:26.238Z

Link: CVE-2026-56690

cve-icon Vulnrichment

Updated: 2026-07-10T13:14:27.453Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')