Impact
Dell PowerStore suffers an OS Command Injection flaw that permits an authenticated user with limited privileges to execute arbitrary commands as root. The vulnerability is a classic input validation failure (CWE-78) that enables complete control over the underlying host when an attacker gains authenticated access. An attacker can compromise confidentiality, integrity, and availability of the entire storage infrastructure.
Affected Systems
The flaw impacts a broad range of Dell PowerStore models, including the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T. No specific firmware or software version identifiers are provided in the public data, so all currently deployed instances should be considered at risk until a patch is applied.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is classified as high severity. The EPSS score is unavailable and the weakness is not listed in the CISA KEV catalog, but the exploit requires only legitimate credentials with limited privileges, which may be obtained through phishing or other credential compromise techniques. Once exploited, the attacker achieves root-level execution on the host operating system. The likely attack vector is through authenticated API or web interface usage in a network‑connected environment, implying that remote or local adversaries with valid credentials can trigger the flaw.
OpenCVE Enrichment