Impact
Dell PowerStore contains an inclusion of functionality from an untrusted control sphere. An authenticated user with limited privileges could potentially exploit this flaw to run arbitrary code with root privileges, thereby compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑829, indicating that the software incorrectly incorporates or processes functionality supplied by an untrusted source.
Affected Systems
Dell PowerStore storage arrays, including models 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. No version information is provided in the data, so all releases of these models are potentially affected.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user with limited privileges, implying that the threat actor must first gain legitimate or compromised credentials and access the management interface or internal network. Once the vulnerable functionality is invoked, the attacker can execute code with root privileges, making exploitation highly destructive.
OpenCVE Enrichment