Impact
Dell PowerStore suffers an Incorrect Authorization flaw that allows a low‑privileged attacker with remote access to gain higher privileges. The weakness is classified as CWE‑863 and can potentially give the attacker full administrative control of the affected storage system.
Affected Systems
The vulnerability applies to Dell PowerStore appliances across a broad range of models, including the 500T, 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200Q, 5200T, 7000T, 9000T, and 9200T families.
Risk and Exploitability
With a CVSS score of 8.8 the issue falls in the high‑severity category. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet the nature of the flaw and the fact that it can be leveraged from remote low‑privileged accounts suggests that it is a realistic threat. An attacker who can reach the appliance’s management network can trigger the privilege escalation without needing additional credentials.
OpenCVE Enrichment