Description
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure leading to Administrative Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Dell PowerStore contains a missing authentication flaw that allows an unauthenticated attacker with network access to the restricted management interface to read sensitive system information from the appliance filesystem. The flaw is a classic case of CWE-306, where the system fails to verify the identity of a caller before permitting use of a critical function. If an attacker obtains internal system data or credentials, they can potentially gain full administrative control over the array.

Affected Systems

The vulnerability affects multiple Dell PowerStore appliances, including the 500, 500T, 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200Q, 5200T, 7000T, 9000T, and 9200T models.

Risk and Exploitability

The CVSS score of 9.8 classifies this as a critical vulnerability. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation at the time of this analysis. However, the lack of authentication combined with the high potential impact makes this an attractive target. The likely attack vector is an unauthenticated user reaching the restricted management interface over the network, a port normally isolated but potentially exposed if connectivity or firewall rules are misconfigured.

Generated by OpenCVE AI on August 31, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Dell PowerStore security update available at https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities
  • Restrict network access to the PowerStore management interface using firewall rules or VPN to ensure only authorized administrators can reach it
  • Monitor the management interface for any unexpected read attempts or anomalous system calls that may indicate reconnaissance attempts

Generated by OpenCVE AI on August 31, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t
Vendors & Products Dell
Dell powerstore 1000t
Dell powerstore 1200t
Dell powerstore 3000t
Dell powerstore 3200q
Dell powerstore 3200t
Dell powerstore 5000t
Dell powerstore 500t
Dell powerstore 5200q
Dell powerstore 5200t
Dell powerstore 7000t
Dell powerstore 9000t
Dell powerstore 9200t

Mon, 31 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Missing Authentication in Dell PowerStore Management Interface

Mon, 31 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerstore 1000t Powerstore 1200t Powerstore 3000t Powerstore 3200q Powerstore 3200t Powerstore 5000t Powerstore 500t Powerstore 5200q Powerstore 5200t Powerstore 7000t Powerstore 9000t Powerstore 9200t
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-31T14:33:06.554Z

Reserved: 2026-07-01T11:04:36.019Z

Link: CVE-2026-58574

cve-icon Vulnrichment

Updated: 2026-08-31T14:33:02.869Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-31T07:17:44.743

Modified: 2026-09-01T21:12:11.590

Link: CVE-2026-58574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T08:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function