Impact
Dell PowerStore contains a missing authentication flaw that allows an unauthenticated attacker with network access to the restricted management interface to read sensitive system information from the appliance filesystem. The flaw is a classic case of CWE-306, where the system fails to verify the identity of a caller before permitting use of a critical function. If an attacker obtains internal system data or credentials, they can potentially gain full administrative control over the array.
Affected Systems
The vulnerability affects multiple Dell PowerStore appliances, including the 500, 500T, 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200Q, 5200T, 7000T, 9000T, and 9200T models.
Risk and Exploitability
The CVSS score of 9.8 classifies this as a critical vulnerability. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation at the time of this analysis. However, the lack of authentication combined with the high potential impact makes this an attractive target. The likely attack vector is an unauthenticated user reaching the restricted management interface over the network, a port normally isolated but potentially exposed if connectivity or firewall rules are misconfigured.
OpenCVE Enrichment