Impact
Dell PowerStore is affected by an OS Command Injection flaw that allows an authenticated user with limited privileges to execute arbitrary system commands with root authority. The vulnerability relies on insufficient input validation when processing privileged operations, enabling attackers to gain full control of the underlying operating system. This represents a high severity compromise that threatens confidentiality, integrity, and availability of the entire storage appliance.
Affected Systems
The affected models include Dell PowerStore 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T and 9200T. No specific firmware or software version ranges are supplied for these models.
Risk and Exploitability
The CVSS score of 8.8 reflects a high impact vulnerability. Because the EPSS score is not available, the exploitation likelihood cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate to the PowerStore management interface; no public or remote exploit is described. Once authenticated, the attacker can leverage the command injection to run commands as root, making the vulnerability potentially exploitable from within the internal network or by compromised local accounts.
OpenCVE Enrichment