Impact
Dell PowerStore suffers from a code injection vulnerability (CWE-94) that allows an authenticated user with limited privileges to execute arbitrary code. If exploited, the attacker can obtain root privileges, enabling full control over the system and its data.
Affected Systems
The vulnerability affects Dell PowerStore storage systems across a broad range of models including the 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 500T, 5200Q, 5200T, 7000T, 9000T, and 9200T series. No specific firmware or software version information is provided in the available data, so all current releases of these models should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity impact. Although the EPSS score is not available, the lack of a KEV listing does not diminish the risk posed by the vulnerability. The requirement for authentication and limited privileges suggests that the attack vector is likely restricted to users who already have some level of access to management interfaces, but an attacker could still elevate to root if the injection succeeds. Given the potential to gain full control, the threat remains significant until a patch is applied.
OpenCVE Enrichment